View only access for User Group 1 folder

View only access for User Group 1 folder

avatar

Hi,

Is there a way for 1 user group to only have access to 1 folder in a vault, without giving access to the whole vault?

All Comments (2)

avatar

Yes, we have multiple groups that should not be able to see each other's data. I'm sure there is more than one way to do this, but here's what we did that works for us:

In DVLS, by default, folders are created with Everyone having all permissions. You will want to modify all of the folders you do not want group 1 to see by removing the Everyone permissions and setting the permissions to allow just the group(s) that should have permissions to those folders.

Using the web client, go to the properties of the vault and set the permission "Add in root" to Custom and select a privileged group (create one, if needed) that will be tasked with creating folders off the root. This is so a folder isn't created accidentally at the root without the appropriate permissions set.

Next, for each of the folders at the root-level, you will need to set the permissions to Custom. Here, the "Grant Access" button is your best friend for quickly adding permissions. For all of the folders that you want to secure from others, you will want to minimally set the View permission to the appropriate group(s), again, creating the groups if they don't already exist.

Repeat the above step for each root folder, securing them so that just the appropriate groups have the correct permissions.

forum image
forum image

Edit: I forgot to add the link to the documentation on securing entries in DVLS: Permissions (devolutions.net)

avatar

Thank you, that has helped greatly. I think I will set the default Permissions to Never so that the custom permissions have to be set for each folder.
Thanks again