Skip to content
Oct 02, 2026 Est. Read Time: 3 mins

How to Create Windows Users, Groups, and Folder Permissions for File Sharing

<h1>How to Create Windows Users, Groups, and Folder Permissions for File Sharing<\/h1><p>Company file sharing should not rely on a single Administrator account for all users. A structured identity and permission model makes access easier to manage and reduces unnecessary privileges.<\/p><p>The basic model is:<\/p><blockquote><strong>User → Group → Folder → Permission<\/strong><\/blockquote><p>This approach allows users to be managed according to their department without assigning permissions individually to every account.<\/p><h2>1. Create the Company Folder Structure<\/h2><p>Assume the company has departments such as Finance, Logistics, Marketing, IT, LAB, and Agro.<\/p><p>The storage structure can be organized as follows:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">E:\\CompanyShare

├── Finance

├── Logistik

├── Marketing

├── IT

├── LAB

└── Agro

<\/pre><h2>2. Create Local Windows Users<\/h2><p>Open <strong>PowerShell as Administrator<\/strong> on the Windows Server.<\/p><p>For example, create a Logistics user:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">net user log1 * /add

<\/pre><p>Windows will request a password for the account.<\/p><p>Create a Finance user:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">net user fin1 * /add

<\/pre><p>Verify the accounts:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">net user log1

net user fin1

<\/pre><h2>3. Create Department Groups<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">net localgroup GG_Company_Finance /add

net localgroup GG_Company_Logistik /add

net localgroup GG_Company_Marketing /add

net localgroup GG_Company_IT /add

net localgroup GG_Company_LAB /add

net localgroup GG_Company_Agro /add

<\/pre><h2>4. Add Users to Groups<\/h2><p>Add each user to the appropriate department group.<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">net localgroup GG_Company_Logistik log1 /add

net localgroup GG_Company_Finance fin1 /add

<\/pre><p>Verify group membership:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">net localgroup GG_Company_Logistik

net localgroup GG_Company_Finance

<\/pre><p>A user can belong to multiple groups when access to multiple departments is required.<\/p><h2>5. Create Department Folders<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">New-Item -ItemType Directory -Path \"E:\\CompanyShare\"


New-Item -ItemType Directory -Path \"E:\\CompanyShare\\Finance\"

New-Item -ItemType Directory -Path \"E:\\CompanyShare\\Logistik\"

New-Item -ItemType Directory -Path \"E:\\CompanyShare\\Marketing\"

New-Item -ItemType Directory -Path \"E:\\CompanyShare\\IT\"

New-Item -ItemType Directory -Path \"E:\\CompanyShare\\LAB\"

New-Item -ItemType Directory -Path \"E:\\CompanyShare\\Agro\"

<\/pre><h2>6. Understanding NTFS Permissions<\/h2><p>Permissions should normally be assigned to <strong>groups<\/strong> rather than individual users.<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">GG_Company_Finance

    ↓

Modify

    ↓

E:\\CompanyShare\\Finance

<\/pre><p>The user <code style=\"background-color: rgb(240, 240, 240);\">fin1<\/code> receives access through the Finance group.<\/p><h2>7. Back Up ACLs Before Making Changes<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">icacls \"E:\\CompanyShare\" /save \"C:\\CompanyShare-before-acl.txt\" /T /C

<\/pre><blockquote><strong>Warning:<\/strong> do not blindly run <code style=\"background-color: rgb(240, 240, 240);\">icacls /reset /T<\/code> on production folders because it can change existing permissions.<\/blockquote><h2>8. Configure Logistics Folder Permissions<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">icacls \"E:\\CompanyShare\\Logistik\" /inheritance:r


icacls \"E:\\CompanyShare\\Logistik\" /grant \"GG_Company_Logistik:(OI)(CI)M\"


icacls \"E:\\CompanyShare\\Logistik\" /grant \"Administrators:(OI)(CI)F\"


icacls \"E:\\CompanyShare\\Logistik\" /grant \"SYSTEM:(OI)(CI)F\"

<\/pre><h2>9. Create the SMB Share<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">New-SmbShare `

  -Name \"Company\" `

  -Path \"E:\\CompanyShare\" `

  -Description \"Company Department Shared Storage\" `

  -ChangeAccess \"BUILTIN\\Users\" `

  -FullAccess \"BUILTIN\\Administrators\"

<\/pre><p>Verify the SMB Share:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">Get-SmbShare -Name \"Company\"


Get-SmbShareAccess -Name \"Company\"

<\/pre><h2>10. Share Permission vs NTFS Permission<\/h2><p>Windows file sharing has two important permission layers:<\/p><ol><li><strong>SMB Share Permission<\/strong><\/li><li><strong>NTFS Permission<\/strong><\/li><\/ol><p>Both layers should be considered during troubleshooting.<\/p><h2>11. Test User Access<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">net use \\\\SERVER-IP\\Company /user:SERVER-NAME\\log1 *

<\/pre><pre class=\"ql-syntax\" spellcheck=\"false\">dir \\\\SERVER-IP\\Company\\Logistik

<\/pre><p>If the Logistics user should not have Finance access, the following should be denied:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">dir \\\\SERVER-IP\\Company\\Finance

<\/pre><h2>12. Test Modify Permission<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">\"SMB TEST\" | Out-File \"\\\\SERVER-IP\\Company\\Logistik\\test.txt\"


Get-Content \"\\\\SERVER-IP\\Company\\Logistik\\test.txt\"


\"UPDATED\" | Out-File \"\\\\SERVER-IP\\Company\\Logistik\\test.txt\"


Remove-Item \"\\\\SERVER-IP\\Company\\Logistik\\test.txt\"

<\/pre><h2>13. Common Mistakes<\/h2><ul><li>Using Administrator as the operational account for all users.<\/li><li>Giving Full Control to all users.<\/li><li>Assigning permissions individually to many users.<\/li><li>Changing ACLs without creating a backup.<\/li><li>Running <code style=\"background-color: rgb(240, 240, 240);\">icacls /reset /T<\/code> on production folders without understanding the consequences.<\/li><li>Assuming Windows Groups and Nextcloud Groups are automatically synchronized.<\/li><\/ul><h2>14. Conclusion<\/h2><blockquote><strong>User → Department Group → NTFS Permission → SMB Share<\/strong><\/blockquote><p>This structure makes user management easier because new users can simply be added to the appropriate department group without repeatedly changing folder permissions.<\/p>