<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limited Access File Structure in Vault Forum</title>
    <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118762#M1599</link>
    <description>&lt;P&gt;&lt;a href="https://forums.autodesk.com/t5/user/viewprofilepage/user-id/10998962"&gt;@mtmarchant&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What out of the box groups did you add this test user to?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2024 18:50:37 GMT</pubDate>
    <dc:creator>ihayesjr</dc:creator>
    <dc:date>2024-10-30T18:50:37Z</dc:date>
    <item>
      <title>Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118690#M1598</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To preface, I am not a Vault expert. I just happen to be the most experienced person on our team, therefore a lot of Vault related tasks get delegated to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to create a permissions structure within our Vault that accomplishes a couple of things:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;We want to prohibit the moving of files and folders&lt;/LI&gt;&lt;LI&gt;We want to prohibit the renaming of folders (preferable to limit file renaming as well, but not a necessity)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Simply put, this is our fundamental folder structure and desired permissions:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mtmarchant_0-1730311832228.png" style="width: 600px;"&gt;&lt;img src="https://forums.autodesk.com/t5/image/serverpage/image-id/1427738iADC6441924C37FB1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mtmarchant_0-1730311832228.png" alt="mtmarchant_0-1730311832228.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have very limited experience working with Vault groups and roles. I have been doing some testing this morning:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I created a test Vault account with a spare license to try out these changes&lt;/LI&gt;&lt;LI&gt;I created two new roles, for simplicity's sake we can call these:&lt;OL&gt;&lt;LI&gt;General Access Role - This role is a copy of an existing role that essentially allows full functionality of Vault (read/write files and folders, rename files/folders, move files/folders, etc.)&lt;/LI&gt;&lt;LI&gt;Limited Access Role - This role is essentially the same as the General Access role, with the exception that the File Rename, File Move, and Folder Rename permissions have been omitted.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;I created two new groups, for simplicity's sake we can call these:&lt;OL&gt;&lt;LI&gt;General Access Group&lt;/LI&gt;&lt;LI&gt;Limited Access Group&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;I then set the Object-based security permissions for the "Limited Access File and Folder Structure" to:&lt;OL&gt;&lt;LI&gt;General Access Group - Read = Allow, Modify = Blank, Delete = Blank, Download = Allow&lt;/LI&gt;&lt;LI&gt;Limited Access Group - Read = Allow, Modify = Allow, Delete = Blank, Download = Allow&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I then tested these permissions out with the test account, and found that I could still rename folders, rename files, and move files/folders.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a bit stumped, and feel like I could easily go in the wrong direction, and am looking for some potential aid. It is very possible that without diligent research I could cause more harm than good, and if it is necessary to get a more experienced individual contracted to help, then I can push for that with my superiors.&lt;BR /&gt;&lt;BR /&gt;I appreciate any input!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 18:21:54 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118690#M1598</guid>
      <dc:creator>mtmarchant</dc:creator>
      <dc:date>2024-10-30T18:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118762#M1599</link>
      <description>&lt;P&gt;&lt;a href="https://forums.autodesk.com/t5/user/viewprofilepage/user-id/10998962"&gt;@mtmarchant&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What out of the box groups did you add this test user to?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 18:50:37 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118762#M1599</guid>
      <dc:creator>ihayesjr</dc:creator>
      <dc:date>2024-10-30T18:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118774#M1600</link>
      <description>&lt;P&gt;&lt;a href="https://forums.autodesk.com/t5/user/viewprofilepage/user-id/10998962"&gt;@mtmarchant&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also recommend that you review this class.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.autodesk.com/autodesk-university/class/Security-Awakens-Defending-Against-First-Order-2017" target="_blank"&gt;Security Awakens: Defending Against the First Order | Autodesk University&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 18:59:35 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118774#M1600</guid>
      <dc:creator>ihayesjr</dc:creator>
      <dc:date>2024-10-30T18:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118784#M1601</link>
      <description>&lt;P&gt;&lt;a href="https://forums.autodesk.com/t5/user/viewprofilepage/user-id/10998962"&gt;@mtmarchant&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another note: assign the user the out-of-the-box Document Editor (Level 1) group.&lt;/P&gt;
&lt;P&gt;This group does not allow users to rename a file or folder.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 19:01:28 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118784#M1601</guid>
      <dc:creator>ihayesjr</dc:creator>
      <dc:date>2024-10-30T19:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118799#M1602</link>
      <description>I'm not currently using any out of the box groups or roles.</description>
      <pubDate>Wed, 30 Oct 2024 19:07:52 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118799#M1602</guid>
      <dc:creator>mtmarchant</dc:creator>
      <dc:date>2024-10-30T19:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118804#M1603</link>
      <description>&lt;P&gt;I recommend that you start with the Out-of-box roles and start with testing the File and Folder rename restrictions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 19:09:44 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13118804#M1603</guid>
      <dc:creator>ihayesjr</dc:creator>
      <dc:date>2024-10-30T19:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122155#M1604</link>
      <description>&lt;P&gt;I've tested out the Document Editor (Level 1) role, and it is prohibiting file and folder renames. An interesting interaction is occurring with the file rename, however. I get the standard message saying "you do not have permission to complete this task. contact your administrator", however, I'm also getting this message:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mtmarchant_0-1730379656190.png" style="width: 600px;"&gt;&lt;img src="https://forums.autodesk.com/t5/image/serverpage/image-id/1428107i16FDE8E2BF969E78/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mtmarchant_0-1730379656190.png" alt="mtmarchant_0-1730379656190.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Additionally, the file is then being checked out by the user. This appears to happen automatically after a file rename attempt.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 13:01:56 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122155#M1604</guid>
      <dc:creator>mtmarchant</dc:creator>
      <dc:date>2024-10-31T13:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122174#M1605</link>
      <description>&lt;P&gt;&lt;a href="https://forums.autodesk.com/t5/user/viewprofilepage/user-id/10998962"&gt;@mtmarchant&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you, I noticed the same error and informed the development team to address this.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 13:08:36 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122174#M1605</guid>
      <dc:creator>ihayesjr</dc:creator>
      <dc:date>2024-10-31T13:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122293#M1606</link>
      <description>&lt;P&gt;&lt;a href="https://forums.autodesk.com/t5/user/viewprofilepage/user-id/10998962"&gt;@mtmarchant&lt;/a&gt;&amp;nbsp;thank you for sharing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I notice in your initial post description that for the groups the permissions were set contrary to the intent you described. In my humble opinion (I'm not a vault expert nor I have enough experience) they should have been as follows:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;General Access Group - Read = Allow, Modify = Allow, Delete = Blank, Download = Allow&lt;/LI&gt;&lt;LI&gt;Limited Access Group - Read = Allow, Modify = Deny/Blank, Delete = Blank, Download = Allow&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I'm not very sure the exact differences between "Blank" or "Deny", if anybody does I believe that it would be beneficial to pinpoint it here for the use-case.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Daniel Ramirez&lt;BR /&gt;CAD Manager&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 13:58:52 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122293#M1606</guid>
      <dc:creator>daniel_ramirez_NIPG</dc:creator>
      <dc:date>2024-10-31T13:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122301#M1607</link>
      <description>&lt;P&gt;&lt;a href="https://forums.autodesk.com/t5/user/viewprofilepage/user-id/15799351"&gt;@daniel_ramirez_NIPG&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Take a look at this Help topic which explains the "Blank" or "None" works.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://help.autodesk.com/view/VAULT/2025/ENU/?guid=GUID-37BD99E4-1189-4383-8531-92B607D74873" target="_blank"&gt;Vault 2025 Help | Access Control Lists (acls) | Autodesk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 14:05:16 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122301#M1607</guid>
      <dc:creator>ihayesjr</dc:creator>
      <dc:date>2024-10-31T14:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122532#M1608</link>
      <description>&lt;P&gt;OK, so I have managed to get one test group and user working with the correct behavior:&lt;BR /&gt;&lt;BR /&gt;New files and folders can be created under the Limited Access folder structure.&lt;BR /&gt;These files and folders cannot be renamed, and they cannot be moved.&lt;BR /&gt;&lt;BR /&gt;However, I need this user to have access to the General Access folder structure to be able to create new files and folders, and rename and move those files and folders.&lt;BR /&gt;&lt;BR /&gt;When I go to add this user to the General Access group, it allows them to rename and move files and folders in the Limited Access folder structure. These are what the Object-Based Security settings look like for the Limited Access folder structure:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mtmarchant_0-1730388794786.png" style="width: 600px;"&gt;&lt;img src="https://forums.autodesk.com/t5/image/serverpage/image-id/1428165iD9124524E42EC648/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mtmarchant_0-1730388794786.png" alt="mtmarchant_0-1730388794786.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If I remove the user from the General Access group, it works just fine. But when they are in that group, even though the Modify is implicitly denied, it allows modification (rename files/folders, move files/folders), though the Limited Access group does not include these permissions (Limited Access group contains only the Document Editor (Level 1) and Document Manager (Level 1) roles).&lt;BR /&gt;&lt;BR /&gt;I'm essentially just wanting to limit files and folders being renamed, and prohibit these files from being moved once they have been checked into the Limited Access folder structure. Users still need read/write access to download these files and check them out and modify as necessary.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 15:37:39 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122532#M1608</guid>
      <dc:creator>mtmarchant</dc:creator>
      <dc:date>2024-10-31T15:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122833#M1609</link>
      <description>&lt;P&gt;You will not be able to restrict them from moving and renaming files and folders under a specific structure and not others.&lt;/P&gt;
&lt;P&gt;The Roles are across all of Vault, not inside of the structure.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 17:39:23 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122833#M1609</guid>
      <dc:creator>ihayesjr</dc:creator>
      <dc:date>2024-10-31T17:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Access File Structure</title>
      <link>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122836#M1610</link>
      <description>Well, that is unfortunate news to hear, considering the workflow we were going for. But, I'm glad I made this forum post, otherwise I would have continued to try to twist and turn to make this workflow work.&lt;BR /&gt;&lt;BR /&gt;Thank you, Irvin, for helping me out with this.</description>
      <pubDate>Thu, 31 Oct 2024 17:42:54 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/vault-forum/limited-access-file-structure/m-p/13122836#M1610</guid>
      <dc:creator>mtmarchant</dc:creator>
      <dc:date>2024-10-31T17:42:54Z</dc:date>
    </item>
  </channel>
</rss>

