---
title: Shared folder permissions...why use groups?
description: Windows has created a false premise that the best way to manage shared folder permissions is with groups. Your users don't think that way.
image: https://blog.empowerid.com/hs-fs/file-19071009-jpg/images/shared_folder_permissions.jpg
---

[![empowerID-logo](https://blog.empowerid.com/hubfs/empowerID-logo.svg "empowerID-logo")](http://www.empowerid.com)

**![phone](https://blog.empowerid.com/hubfs/images/phone.svg)   1-877-996-4276   **or**  +1 (614) 652-6825**

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/220903377569) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/company/85780) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/EmpowerID) [![Share on pinterest](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/pinterest-color.png?width=24&name=pinterest-color.png) ](http://www.youtube.com/user/empowerID)

# All-In-One Identity Management and Cloud Security

Emerging technologies are challenging old paradigms and unveiling new ways of approaching the security discipline that enables the right individuals to access the right resources at the right times for the right reasons.

EmpowerID has embedded innovative technologies in every aspect, providing flexible and mature IAM capabilities in the cloud, on premise and in hybrid environments, addressing the mission-critical need across increasingly heterogeneous technology environments, and meeting increasingly rigorous compliance requirements.

# Shared folder permissions...why use groups?

Posted by [Edward Killeen](https://blog.empowerid.com/blog-1/author/edward-killeen) on Mon, Jan 28, 2013

- [Tweet](https://twitter.com/share)

![Shared folder permissions](https://blog.empowerid.com/hs-fs/file-19071009-jpg/images/shared_folder_permissions.jpg)Windows has created a false premise that the best way to manage [shared folder permissions](http://www.empowerid.com/products/filesharemanager) is with groups.  You grant access to the folder by way of an AD security group, then users request membership in that group.  That's the way NTFS works but ***is it the way users think*?**

Users want access to a resource; they want access to a folder.  They don't want membership in a group.  Of course, they need membership in a group, but they don't know that.  So, why would you force users to ask for access in such a roundabout way?  It should be simple and the mechanism of how it is happening in the background shouldn't matter to your user.  The premise is: users will think of what they want access to and should be able to request it directly.

EmpowerID File Share Manager puts a 360 degree view of file shares in front of your user.  They can view what roles and/or groups they are a member of and see the resultant access to shared folders.  Or they can view the shared folders they have access to and see the roles and or groups that make that happen.

And, most importantly, they can search on folders to request access.  When they request access a few things happen unbeknownst to them.  If they are allowed access directly, they are granted access.  If a resource owner needs to approve access, it will route the approval to the owner and let the user know that it needs an approval before granting access.

EmpowerID does this by putting a user into a role which has access to that resource (shared folder in this case).  By putting the user in a role and not an AD group it saves the user from being a member of too many groups and ultimately getting token bloat.  Token bloat seems like a made up malady but it is bad.  The more groups your user is in, the larger their token gets.  At 1015 memberships, the token exceeds allowable size and the user cannot log in.  As it gets over 256 memberships, authentication slows down and kerberos has a tendency to lock up with some applications.

So, by managing your shared folders with a dedicated self service portal, your users will have greater and easier access to shared folders, request access in a more intuitive manner, control harmful afflictions like token bloat, and reduce your dependence on an outdated technology like groups.

But you really don't stop there.  That same self service portal can be used by the resource owners to see who has access to their resources (even if granted via groups the old fashioned way).  They can grant and revoke access to their folders either by searching from the user or the resource.  Most importantly, they can attest to the correct access from the resource side on a regular scheduled basis to meet auditing requirements.

Speaking of our friends the auditors, they might be even more resource oriented than the users.  They need to track who has access to a resource and it costs you money and time to have them try to disentangle all of the resultant access from nested groups.  Having them look directly at the resource is, after all, what they need.

Think about the problem of groups from their perspective.  If a group is giving access to a shared folder, what happens if you're also using it for another purpose and people just keep getting added to it.  Your auditing friend wants to be able to see that easily.  EmpowerID solves that issue in another way, too. 

We use hidden system managed groups and use them in a way that maximally reduces token bloat.  The goal is to reduce the number of groups created to assign permissions and to completely control the membership of these groups so people can’t use them for other purposes and add members which would inadvertently grant access to the folders.  We reject any outside additions or deletions of user to these groups.

The debate has raged for years on groups vs. roles, especially with regard to Active Directory and Windows permissions.  The answer is easy: using groups is the old way; using roles is the new way.  Using groups is letting the technology manage the way you do business.  Using roles is making the way you do business lead the technology.  Especially with shared folder permissions.

[![Demo Shared Folder Permissions  by resource and role](https://no-cache.hubspot.com/cta/default/174819/b8617526-4d7b-4748-9900-d87e1eea3a7b.png)](https://cta-redirect.hubspot.com/cta/redirect/174819/b8617526-4d7b-4748-9900-d87e1eea3a7b)

 Tags: [Role Based Access Control (RBAC)](https://blog.empowerid.com/blog-1/topic/role-based-access-control-rbac)

### About EmpowerID

EmpowerID is the all-in-one Identity Management and Cloud Security platform designed for people.  Globally managing millions of identities in diverse enterprises, EmpowerID offers comprehensive provisioning, single sign-on and access governance coupled with an industry leading user experience. 

Built on a single codebase for manageability and scalability, EmpowerID ships with a powerful API, a visual workflow designer and over 400 ready-to-use workflows for rapid deployment.

 

[![Free Evaluation of EmpowerID](https://no-cache.hubspot.com/cta/default/174819/daebe087-5275-487d-bf53-bb1d39fb9dc4.png)](https://cta-redirect.hubspot.com/cta/redirect/174819/daebe087-5275-487d-bf53-bb1d39fb9dc4)

### Latest Posts

### Posts by category

- [2-Factor (2)](https://blog.empowerid.com/blog-1/topic/2-factor)
- [Access Governance (36)](https://blog.empowerid.com/blog-1/topic/access-governance)
- [Active Directory (46)](https://blog.empowerid.com/blog-1/topic/active-directory)
- [Attestation (4)](https://blog.empowerid.com/blog-1/topic/attestation)
- [authentication (6)](https://blog.empowerid.com/blog-1/topic/authentication)
- [authorization (2)](https://blog.empowerid.com/blog-1/topic/authorization)
- [azure (1)](https://blog.empowerid.com/blog-1/topic/azure)
- [Azure security (2)](https://blog.empowerid.com/blog-1/topic/azure-security)
- [azuread (1)](https://blog.empowerid.com/blog-1/topic/azuread)
- [Cisco (1)](https://blog.empowerid.com/blog-1/topic/cisco)
- [Citrix (1)](https://blog.empowerid.com/blog-1/topic/citrix)
- [cloud (1)](https://blog.empowerid.com/blog-1/topic/cloud)
- [cloud security (28)](https://blog.empowerid.com/blog-1/topic/cloud-security)
- [consumers (2)](https://blog.empowerid.com/blog-1/topic/consumers)
- [Data Governance (5)](https://blog.empowerid.com/blog-1/topic/data-governance)
- [dataprivacy (1)](https://blog.empowerid.com/blog-1/topic/dataprivacy)
- [DirSync (1)](https://blog.empowerid.com/blog-1/topic/dirsync)
- [eic (1)](https://blog.empowerid.com/blog-1/topic/eic)
- [Federation (6)](https://blog.empowerid.com/blog-1/topic/federation)
- [Gartner (1)](https://blog.empowerid.com/blog-1/topic/gartner)
- [GDPR (2)](https://blog.empowerid.com/blog-1/topic/gdpr)
- [Governance and Regulatory Compliance (4)](https://blog.empowerid.com/blog-1/topic/governance-and-regulatory-compliance)
- [GRC (3)](https://blog.empowerid.com/blog-1/topic/grc)
- [Group Management (12)](https://blog.empowerid.com/blog-1/topic/group-management)
- [IAG (4)](https://blog.empowerid.com/blog-1/topic/iag)
- [IAM (34)](https://blog.empowerid.com/blog-1/topic/iam)
- [IDaaS (1)](https://blog.empowerid.com/blog-1/topic/idaas)
- [Identity and Access Management (IAM) (68)](https://blog.empowerid.com/blog-1/topic/identity-and-access-management-iam)
- [Identity Management (6)](https://blog.empowerid.com/blog-1/topic/identity-management)
- [iga (1)](https://blog.empowerid.com/blog-1/topic/iga)
- [M365 security (1)](https://blog.empowerid.com/blog-1/topic/m365-security)
- [Magic Quadrant (1)](https://blog.empowerid.com/blog-1/topic/magic-quadrant)
- [O365 (1)](https://blog.empowerid.com/blog-1/topic/o365)
- [Office 365 (3)](https://blog.empowerid.com/blog-1/topic/office-365)
- [open policy agent (1)](https://blog.empowerid.com/blog-1/topic/open-policy-agent)
- [Palo Alto (1)](https://blog.empowerid.com/blog-1/topic/palo-alto)
- [Password management (13)](https://blog.empowerid.com/blog-1/topic/password-management)
- [Privacy and EU-US Data Transfers (1)](https://blog.empowerid.com/blog-1/topic/privacy-and-eu-us-data-transfers)
- [Privacy Shield (1)](https://blog.empowerid.com/blog-1/topic/privacy-shield)
- [Radius (1)](https://blog.empowerid.com/blog-1/topic/radius)
- [RBAC (2)](https://blog.empowerid.com/blog-1/topic/rbac)
- [Role Based Access Control (RBAC) (40)](https://blog.empowerid.com/blog-1/topic/role-based-access-control-rbac)
- [SAML (4)](https://blog.empowerid.com/blog-1/topic/saml)
- [Separation of Duties (2)](https://blog.empowerid.com/blog-1/topic/separation-of-duties)
- [SharePoint (8)](https://blog.empowerid.com/blog-1/topic/sharepoint)
- [siemens (1)](https://blog.empowerid.com/blog-1/topic/siemens)
- [Single Sign-on (1)](https://blog.empowerid.com/blog-1/topic/single-sign-on)
- [Single Sign-on (SSO) (26)](https://blog.empowerid.com/blog-1/topic/single-sign-on-sso)
- [social media (1)](https://blog.empowerid.com/blog-1/topic/social-media)
- [SSO (3)](https://blog.empowerid.com/blog-1/topic/sso)
- [User provisioning (28)](https://blog.empowerid.com/blog-1/topic/user-provisioning)
- [VDS (1)](https://blog.empowerid.com/blog-1/topic/vds)
- [Virtual Directory (28)](https://blog.empowerid.com/blog-1/topic/virtual-directory)
- [WS-Fed (2)](https://blog.empowerid.com/blog-1/topic/ws-fed)

### Subscribe via E-mail

Share This Page

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](http://www.facebook.com/share.php?u=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F262507%2FShared-folder-permissions-why-use-groups%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F262507%2FShared-folder-permissions-why-use-groups%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F262507%2FShared-folder-permissions-why-use-groups%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F262507%2FShared-folder-permissions-why-use-groups%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check%20out%20https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F262507%2FShared-folder-permissions-why-use-groups%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F262507%2FShared-folder-permissions-why-use-groups%3Futm_medium%3Dsocial%26utm_source%3Demail)

![](https://blog.empowerid.com/hubfs/images/logo-empowerid.svg)

4393 Tuller Road  
Dublin OH

EmpowerID is a registered trademark and  
trade name of The Dot Net Factory, LLC.  
EmpowerID

© 2021 EmpowerID

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Edward Killeen",
    "url" : "https://blog.empowerid.com/blog-1/author/edward-killeen"
  },
  "datePublished" : "2013-01-28T20:53:00.000Z",
  "headline" : "Shared folder permissions...why use groups?",
  "image" : [ "https://blog.empowerid.com/hs-fs/file-19071009-jpg/images/shared_folder_permissions.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.empowerid.com/blog-1/bid/262507/Shared-folder-permissions-why-use-groups",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.empowerid.com/hubfs/Asset%201.svg"
    },
    "name" : "EmpowerID"
  }
}
```