How can I restrict user access to a subfolder of a shared folder?
Last modified date:
2026-01-26
Applicable Products
- QTS
- QuTS hero
- QuTScloud
Instructions for QTS and QuTScloud
- Log in to your QNAP operating system as an administrator.
- Open Control Panel.
- Enable advanced folder permissions.
- Go to Privilege > Shared Folders > Advanced Permissions.
- Select Enable Advanced Folder Permissions.

- Click Apply.
- Enabled access-based enumeration settings on the shared folder.
- Go to Privilege > Shared Folders > Shared Folder.
- Locate the shared folder.
- Under Action, click the Edit Properties icon.
The Edit Properties window opens. - Select Enable access-based share enumeration (ABSE).
- Select Enable access-based enumeration (ABE).

- Click OK.
A confirmation message appears. - Click Yes.
- Edit user access permissions on a subfolder.
- Back in Privilege > Shared Folders > Shared Folder, locate the shared folder again.
- Under Action, click the Edit Shared Folder Permission icon.
The Edit Shared Folder Permission window opens. - In the folder navigation panel, expand the shared folder to reveal its subfolders.
- Select a subfolder to edit user access permissions.

- Choose one of the following actions:
- Select one of the following to change a user's access permissions: Read Only, Read/Write, Deny Access.
- Select a user and click Remove to remove the user's access to the subfolder.
- Click Add to grant a user access to the subfolder.
- Click Apply.
Instructions for QuTS hero
- Log in to QuTS hero as an administrator.
- Open Control Panel.
- Configure the shared folder permissions first.
- Go to Privilege > Shared Folders > Shared Folder.
- Locate the shared folder.
- Under Action, click the Edit Shared Folder Permission icon.
The Edit Shared Folder Permission window opens. - Go to the Users and groups permission tab.
- Select Individual permissions to separately configure protocol permissions and ACL permissions.ImportantThis step is required if you want to edit permissions for a subfolder separately from its parent shared folder.
- Identify the user or user group you want to configure permissions for.TipIf an existing user or user group is not listed, click Add Users to add.
- Select Read/Write for the user or user group.

- Optional: Remove the Everyone group (if applicable).
- Click Apply.
- Configure the subfolder permissions.ImportantTo configure the permissions of a subfolder separately from its parent shared folder, you must enable Individual permissions in step 3e above.
- In the left panel, open the shared folder and select a subfolder.
- Next to Permission style, select Windows Special Permissions.

- Select one or more inheritance permission policies:
- Replace all file and subfolder permissions with inherited permissions from this folder
- Disable inheritance and remove all inherited permissions from this folder (this option is only available to subfolders)
- Disable inheritance and convert inherited permissions on this folder into explicit permissions (this option is only available to subfolders)
- Under Principal, identify the user or user group you want to configure permissions for.TipIf an existing user or user group is not listed, click Add Users to add.
- Under Action, click the Edit icon.
The Edit Principal window opens.
- Under Apply to, select the scope of the permissions.
- Select or deselect one or more permissions to grant the user.NoteSelecting Full control selects and grants all permissions to the user.
- Optional: Select Only apply these permissions to files and subfolders within this folder.
- Click OK.