
Reputation: 183

How to set permissions to all users on a new share folder , by c# code?

How to set permissions to all users on a new share folder , by c# code? this is my code to add share folder:

public static string sharedFolder()
        // create a directory
        // Create a ManagementClass object
        ManagementClass managementClass = new ManagementClass("Win32_Share");
        // Create ManagementBaseObjects for in and out parameters
        ManagementBaseObject inParams = managementClass.GetMethodParameters("Create");
        ManagementBaseObject outParams;
        // Set the input parameters
        inParams["Description"] = "My Files Share";
        inParams["Name"] = "My Files Share";
        inParams["Path"] = @"C:\MyTestShare";
        inParams["Type"] = 0x0; // Disk Drive
        // Invoke the method on the ManagementClass object
        //InvokeMethodOptions _invokeMethodOptions=new InvokeMethodOptions.InfiniteTimeout.h
        outParams = managementClass.InvokeMethod("Create", inParams,null);
        // AddDirectorySecurity(inParams["Path"].ToString());
        // Check to see if the method invocation was successful
        if ((uint)(outParams.Properties["ReturnValue"].Value) != 0)

            return ("Unable to share directory.");

       return ("Able to share directory.");

    catch (Exception e)
        throw new Exception(e.Message);

Upvotes: 1

Views: 6981

Answers (2)

Valery Letroye
Valery Letroye

Reputation: 1095

I have been googling for that too and mainly found unanswered questions like this one.

Here is the code I wrote with all the pieces of code found at different place:

public static void CreateSharedFolder(string FolderPath, string ShareName, string Description)
        // Create a ManagementClass object
        ManagementClass managementClass = new ManagementClass("Win32_Share");

        // Create ManagementBaseObjects for in and out parameters
        ManagementBaseObject inParams = managementClass.GetMethodParameters("Create");

        ManagementBaseObject outParams;

        // Set the input parameters
        inParams["Description"] = Description;
        inParams["Name"] = ShareName;
        inParams["Path"] = FolderPath;
        inParams["Type"] = 0x0; // Disk Drive

        //Another Type:
        // DISK_DRIVE = 0x0
        // PRINT_QUEUE = 0x1
        // DEVICE = 0x2
        // IPC = 0x3
        // DISK_DRIVE_ADMIN = 0x80000000
        // PRINT_QUEUE_ADMIN = 0x80000001
        // DEVICE_ADMIN = 0x80000002
        // IPC_ADMIN = 0x8000003

        //inParams["MaximumAllowed"] = 2;
        inParams["Password"] = null;

        NTAccount everyoneAccount = new NTAccount(null, "EVERYONE");
        SecurityIdentifier sid = (SecurityIdentifier)everyoneAccount.Translate(typeof(SecurityIdentifier));
        byte[] sidArray = new byte[sid.BinaryLength];
        sid.GetBinaryForm(sidArray, 0);

        ManagementObject everyone = new ManagementClass("Win32_Trustee");
        everyone["Domain"] = null;
        everyone["Name"] = "EVERYONE";
        everyone["SID"] = sidArray;

        ManagementObject dacl = new ManagementClass("Win32_Ace");
        dacl["AccessMask"] = 2032127;
        dacl["AceFlags"] = 3;
        dacl["AceType"] = 0;
        dacl["Trustee"] = everyone; 

        ManagementObject securityDescriptor = new ManagementClass("Win32_SecurityDescriptor");
        securityDescriptor["ControlFlags"] = 4; //SE_DACL_PRESENT 
        securityDescriptor["DACL"] = new object[] { dacl };

        inParams["Access"] = securityDescriptor;

        // Invoke the "create" method on the ManagementClass object
        outParams = managementClass.InvokeMethod("Create", inParams, null);

        // Check to see if the method invocation was successful
        var result = (uint)(outParams.Properties["ReturnValue"].Value);
        switch (result)
            case 0:
                Console.WriteLine("Folder successfuly shared.");
            case 2:
                Console.WriteLine("Access Denied");
            case 8:
                Console.WriteLine("Unknown Failure");
            case 9:
                Console.WriteLine("Invalid Name");
            case 10:
                Console.WriteLine("Invalid Level");
            case 21:
                Console.WriteLine("Invalid Parameter");
            case 22:
                Console.WriteLine("Duplicate Share");
            case 23:
                Console.WriteLine("Redirected Path");
            case 24:
                Console.WriteLine("Unknown Device or Directory");
            case 25:
                Console.WriteLine("Net Name Not Found");
                Console.WriteLine("Folder cannot be shared.");
    catch (Exception ex)
        Console.WriteLine("Error:" + ex.Message);

internal static void RemoveSharedFolder(string ShareName)
        // Create a ManagementClass object
        ManagementClass managementClass = new ManagementClass("Win32_Share");
        ManagementObjectCollection shares = managementClass.GetInstances();
        foreach (ManagementObject share in shares)
            if (Convert.ToString(share["Name"]).Equals(ShareName))
                var result = share.InvokeMethod("Delete", new object[] { });

                // Check to see if the method invocation was successful
                if (Convert.ToInt32(result) != 0)
                    Console.WriteLine("Unable to unshare directory.");
                    Console.WriteLine("Folder successfuly unshared.");
    catch (Exception ex)
        Console.WriteLine("Error:" + ex.Message);

"FolderPath" must exists.

Upvotes: 14

Erik Philips
Erik Philips

Reputation: 54636

I'm assuming your description of everyone is "all users".

MSDN Create Method of the Win32_Share Class


Access [in]

Security descriptor for user level permissions. A security descriptor contains information about the permissions, owner, and access capabilities of the resource. If this parameter is not supplied or is NULL, then Everyone has read access to the dhare. For more information, see Win32_SecurityDescriptor and Changing Access Security on Securable Objects.

Otherwise, according to MSDN - Chaning Access Security on Securable Objects you need to use the Win32_LogicalShareSecuritySetting class with the SetSecurityDescriptor method described on MSDN - SetSecurityDescriptor Method of the Win32_LogicalShareSecuritySetting Class

Upvotes: 2

Related Questions