#How to interrupt or switch of inheritance from volumes to qtrees while setting DACLs

1 messages · Page 1 of 1 (latest)

magic moss
#

Hi,

I want to replace DACLs for Qtrees on the command line with creating file-directory policies, security descriptors and eventually

::> vserver security file-directory ntfs dacl add ...

However, when I create and start the task to create the DACL, the Everyone Full-Controle ACE gets inherited from the volume.

I tried to replace the DACL on the volume but than this replacement gets inherited to the qtrees and subfolders as well.

Is there a way to either disable inheritance from volume to qtrees or interrupt the inheritance while deleting it on the volume level?

I'm using Ontap 9.8P14

fallow zealot
#

@fleet otter something you could assist with here?

fleet otter
#

@fallow zealot @magic moss looking into it...

magic moss
#

@fleet otter It works if you create the policy task with propagate and, when creating the DACLs, set "-apply-to this-folder" only. After applying the policy, you can than stop the respective job after the ACLs are set on the root of the volume.