Hi,
I've been looking for an answer for this issue for months now to no avail. Maybe someone here can help.
Windows 2000 server -
Shared Data directory with share permissions wide open to all users (all sub directories locked down with NTFS permissions).
Engineering subdirectory - Not allowing inheritance. Engineering DLG (domain local group) had modify permissions, but a regulatory requirement dictated that users in this group could not delete ANY files or folders. Since modify permissions natively allows the delete permission (but not the delete subfolders & files), I unchecked the delete permission within the "Advanced" properties of the Access Control Settings. After doing this and going back to the previous screen (security properties), the modify permission is unchecked and only Read, Write, Read & Execute, and List Folder Contents are checked.
At the surface, this would seem fine; however, now users cannot even save files to this directory (but they should be able to based on the Write persmission). While saving, a bogus error is output, and an empty file with the chosen name is saved with no data in it. Unfortuantely, this is repeatable within every PC and server in my environment. Alternatively, if I explictily "Deny" delete permissions (within the Advanced properties of the Access Control Settings) it maintains the "modify" attribute, but users can still delete files and folders.
All servers and PC's are up to current service packs and hotfixes, and there are no share vs. NTFS permission conflicts or NTFS vs. NTFS permission conflicts (i.e. least restrictive vs. most restrictive, etc...).
Any thoughts?