You are viewing limited content. For full access, please sign in.

Question

Question

set files to no delete by anyone

asked on March 22, 2023

I wonder if anyone knows a straightforward way to set the files in a particular folder to no delete regardless of user rights? I figure it's out of bounds in some way, but it would be cool if no one but LF admins could delete and all other groups/users could not.

 

Thanks

 

Frank

0 0

Answer

SELECTED ANSWER
replied on March 24, 2023

If you have the records management feature, you could grant rights to records management to only IT so that IT can put a hold on the record, which will prevent modification by anyone until the hold is removed (which only IT would be able to do).

0 0

Replies

replied on March 22, 2023

Making the contents of a folder undeletable is easy, you can add an access control entry (ACE) on the Everyone group denying delete. Deny overrides Allow, and all users belong to Everyone, so now no user can delete. Admins are not excepted from this, so they would not be able to delete.

If you need admins to be able to delete, then what you really want is for most users to not inherit rights to delete the contents of the folders. At some point in your folder tree, you must have granted users the right to delete in a way that inherits down to the folder you want to secure. Can you change that ACE, or move the folder so that it is no longer under that ACE? It may take some planning, but the best way to manage security is to try to not grant more rights than you need to, because selectively removing them is tricky.

2 0
replied on March 22, 2023

Hey Brian!

 

Thanks! This was just what I needed to discuss with my partner who has handled most of the access rights so far.

 

Frank

1 0
replied on March 24, 2023

Thanks Kevin!

 

That helps me avoid denies and we do have records management.

 

I will try your suggestion!

 

Frank

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.