Skip to main content
NetApp Knowledge Base

Unexpected removal of existing NTFS permissions when adding users/groups

Views:
16
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

Applies to

  • NetApp ONTAP 
  • AFF-C250 (and other ONTAP-based systems)
  • CIFS/SMB shares with NTFS security style
  • Environments performing Active Directory domain migration 
  • Customers migrating data and NTFS ACLs between shares/SVMs

Issue

After migrating data and NTFS permissions (ACLs) from a source CIFS share to a destination share in a new domain, administrators observed the following behavior:

  • When adding a new user or group to NTFS permissions on a subfolder (using either the Security tab or Advanced Security Settings), existing users/groups are unexpectedly removed from the Security tab.
  • This issue is reproducible on the destination share only; it does not occur on the original source share.
  • The root of the destination share uses explicit NTFS ACLs with inheritance disabled, similar to the source.
  • Example log/behavior:
    • Data and NTFS permissions copied from \\192.168.1.102\share1 (source, SVM: src_svm) to \\192.168.1.155\new_share (destination, SVM: svm-test-fs).
    • After copying, adding a user/group to a subfolder under /new_share removes existing ACEs for other users/groups.
    • ONTAP security traces show no share-level or ONTAP configuration issues.

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.