<h1>How to Create Windows Users, Groups, and Folder Permissions for File Sharing<\/h1><p>Company file sharing should not rely on a single Administrator account for all users. A structured identity and permission model makes access easier to manage and reduces unnecessary privileges.<\/p><p>The basic model is:<\/p><blockquote><strong>User → Group → Folder → Permission<\/strong><\/blockquote><p>This approach allows users to be managed according to their department without assigning permissions individually to every account.<\/p><h2>1. Create the Company Folder Structure<\/h2><p>Assume the company has departments such as Finance, Logistics, Marketing, IT, LAB, and Agro.<\/p><p>The storage structure can be organized as follows:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">E:\\CompanyShare
├── Finance
├── Logistik
├── Marketing
├── IT
├── LAB
└── Agro
<\/pre><h2>2. Create Local Windows Users<\/h2><p>Open <strong>PowerShell as Administrator<\/strong> on the Windows Server.<\/p><p>For example, create a Logistics user:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">net user log1 * /add
<\/pre><p>Windows will request a password for the account.<\/p><p>Create a Finance user:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">net user fin1 * /add
<\/pre><p>Verify the accounts:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">net user log1
net user fin1
<\/pre><h2>3. Create Department Groups<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">net localgroup GG_Company_Finance /add
net localgroup GG_Company_Logistik /add
net localgroup GG_Company_Marketing /add
net localgroup GG_Company_IT /add
net localgroup GG_Company_LAB /add
net localgroup GG_Company_Agro /add
<\/pre><h2>4. Add Users to Groups<\/h2><p>Add each user to the appropriate department group.<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">net localgroup GG_Company_Logistik log1 /add
net localgroup GG_Company_Finance fin1 /add
<\/pre><p>Verify group membership:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">net localgroup GG_Company_Logistik
net localgroup GG_Company_Finance
<\/pre><p>A user can belong to multiple groups when access to multiple departments is required.<\/p><h2>5. Create Department Folders<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">New-Item -ItemType Directory -Path \"E:\\CompanyShare\"
New-Item -ItemType Directory -Path \"E:\\CompanyShare\\Finance\"
New-Item -ItemType Directory -Path \"E:\\CompanyShare\\Logistik\"
New-Item -ItemType Directory -Path \"E:\\CompanyShare\\Marketing\"
New-Item -ItemType Directory -Path \"E:\\CompanyShare\\IT\"
New-Item -ItemType Directory -Path \"E:\\CompanyShare\\LAB\"
New-Item -ItemType Directory -Path \"E:\\CompanyShare\\Agro\"
<\/pre><h2>6. Understanding NTFS Permissions<\/h2><p>Permissions should normally be assigned to <strong>groups<\/strong> rather than individual users.<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">GG_Company_Finance
↓
Modify
↓
E:\\CompanyShare\\Finance
<\/pre><p>The user <code style=\"background-color: rgb(240, 240, 240);\">fin1<\/code> receives access through the Finance group.<\/p><h2>7. Back Up ACLs Before Making Changes<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">icacls \"E:\\CompanyShare\" /save \"C:\\CompanyShare-before-acl.txt\" /T /C
<\/pre><blockquote><strong>Warning:<\/strong> do not blindly run <code style=\"background-color: rgb(240, 240, 240);\">icacls /reset /T<\/code> on production folders because it can change existing permissions.<\/blockquote><h2>8. Configure Logistics Folder Permissions<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">icacls \"E:\\CompanyShare\\Logistik\" /inheritance:r
icacls \"E:\\CompanyShare\\Logistik\" /grant \"GG_Company_Logistik:(OI)(CI)M\"
icacls \"E:\\CompanyShare\\Logistik\" /grant \"Administrators:(OI)(CI)F\"
icacls \"E:\\CompanyShare\\Logistik\" /grant \"SYSTEM:(OI)(CI)F\"
<\/pre><h2>9. Create the SMB Share<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">New-SmbShare `
-Name \"Company\" `
-Path \"E:\\CompanyShare\" `
-Description \"Company Department Shared Storage\" `
-ChangeAccess \"BUILTIN\\Users\" `
-FullAccess \"BUILTIN\\Administrators\"
<\/pre><p>Verify the SMB Share:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">Get-SmbShare -Name \"Company\"
Get-SmbShareAccess -Name \"Company\"
<\/pre><h2>10. Share Permission vs NTFS Permission<\/h2><p>Windows file sharing has two important permission layers:<\/p><ol><li><strong>SMB Share Permission<\/strong><\/li><li><strong>NTFS Permission<\/strong><\/li><\/ol><p>Both layers should be considered during troubleshooting.<\/p><h2>11. Test User Access<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">net use \\\\SERVER-IP\\Company /user:SERVER-NAME\\log1 *
<\/pre><pre class=\"ql-syntax\" spellcheck=\"false\">dir \\\\SERVER-IP\\Company\\Logistik
<\/pre><p>If the Logistics user should not have Finance access, the following should be denied:<\/p><pre class=\"ql-syntax\" spellcheck=\"false\">dir \\\\SERVER-IP\\Company\\Finance
<\/pre><h2>12. Test Modify Permission<\/h2><pre class=\"ql-syntax\" spellcheck=\"false\">\"SMB TEST\" | Out-File \"\\\\SERVER-IP\\Company\\Logistik\\test.txt\"
Get-Content \"\\\\SERVER-IP\\Company\\Logistik\\test.txt\"
\"UPDATED\" | Out-File \"\\\\SERVER-IP\\Company\\Logistik\\test.txt\"
Remove-Item \"\\\\SERVER-IP\\Company\\Logistik\\test.txt\"
<\/pre><h2>13. Common Mistakes<\/h2><ul><li>Using Administrator as the operational account for all users.<\/li><li>Giving Full Control to all users.<\/li><li>Assigning permissions individually to many users.<\/li><li>Changing ACLs without creating a backup.<\/li><li>Running <code style=\"background-color: rgb(240, 240, 240);\">icacls /reset /T<\/code> on production folders without understanding the consequences.<\/li><li>Assuming Windows Groups and Nextcloud Groups are automatically synchronized.<\/li><\/ul><h2>14. Conclusion<\/h2><blockquote><strong>User → Department Group → NTFS Permission → SMB Share<\/strong><\/blockquote><p>This structure makes user management easier because new users can simply be added to the appropriate department group without repeatedly changing folder permissions.<\/p>