You don’t currently have permission to access this folder Issue -Power Shell Add-NTFSAccess

Hi Guys,

I was dealing with this issue a long time. And I want to share this information with you because it is important to you understand the security architecture of Windows.

Actually you don’t have access, but try to understand the word “CURRENTLY”. That means that you could have access if you click on “Continue”.

What happens next? Well, this behavior is by design. –> and those are not my own words but the official Microsoft declaration about this.

The main limitation is that Windows Explorer design does not support the running of multiple process instances in different security contexts in an interactive user session.

See bellow the actual warning will add your Admin account to the ACL.

Workaround 1

Create a security group, make that group a local administrator member in the file system server and add NTFS permissions to that group via Power Shell. Since Power Shell opened as Administrator does not need any elevation the cmdlets bellow will work.

Add-NTFSAccess -AccessRights FullControl -Account DOMAIN\Security_Group -Path “D:\Folder1\Share1\Share2” -AccessType Allow -AppliesTo ThisFolderSubfoldersAndFiles -PassThru

Workaround 2

To avoid changing permissions in a folder that’s accessible only to administrators, consider using another program that can run elevated instead of using Windows Explorer. Examples include Command Prompt, PowerShell, and the Computer Management MMC snap-in for share management.

Workaround 3
If you have an application-specific folder that’s locked down to prevent ordinary users from accessing it, you can also add permissions for a custom group and then add authorized users to that group. For example, consider a scenario in which an application-specific folder grants access only to the Administrators group and to the System account. In this situation, create a domain or a local AppManagers group, and then add authorized users to it. Then, use a utility such as icacls.exe, the security tab of the folder’s Properties dialog box, or the PowerShell Set-Acl cmdlet to grant the AppManagers group Full Control of the folder, in addition to the existing permissions.

Users who are members of AppManagers will now be able to use Windows Explorer to browse the folder without UAC having to change the folder’s permissions. Be aware that this alternative applies only to application-specific folders. You should never make any permission changes to folders that are part of the Windows operating system, such as C:\Windows\ServiceProfiles.

More info in the official Microsoft KB and you can find it in this link. Microsoft KB950934

Cheers!