I am setting up my first windows 2000 domain, and am having a huge problem.
There are several groups with policies that redirect the “my documents” folders to a share (categorized by group/division/user) on the server. eg. homefolder/clerical/accounts/%username%.
This is the problem i having, i need a group, say clerical, to have read and modify access to the files created by members of the same group, but they must only have deletion rights to the files in their own folders. I have jury rigged it by giving the individual owners full rights, and this works, but what if my network was 3000 users, doing that on a one on one basis is ridiculous