When a user accesses a folder over the network, two checks take place: Share permissions (at the sharing level) and NTFS permissions (at the file system level). The result is the more restrictive permission of the two.
- Share = Full Control for the relevant group, and the real control is done at the NTFS level — this is the accepted practice.
- NTFS: Read, Write, Modify, Full Control.
- Inheritance — permissions descend from the parent folder; breaking inheritance creates exceptions that are hard to maintain.