Can't delete folders on windows share migrated from nas
I have a bunch of macs on various versions of macos from 10.9 - 10.13. They had a qnap nas, and previously migrated all of the files to a windows server 2012 r2 share before I was involved. Users can delete files, but can't delete folders. When trying to delete a folder, they receive an error - "The operation can't be completed because you don't have permission to access of the items." Even though the folder is empty. They are able to open it, and can create files in it. They can rename the folder, and move it anywhere up/down in the file system. They just can't delete it. If I go into a folder in finder and make a dummy subfolder and then try to delete the folder, it deletes the subfolder but gives the error about the parent folder (the one that was brought over from the nas).
The server is setup as a domain controller, but no systems (pc or mac) are added to the domain. It was meant as a file server, but the previous person configured a whole domain.
Things I've tried:
- resetting owner and permission on the files (multiple times to make sure it propagated through)
- connecting to smb://servername and smb://serverip
- deleting from different macs, who all connect to the share as different users
- disable .ds_store files and directory caching, per https://support.apple.com/en-us/HT208209
- rebooting the server
smbutil statshares -a results:
SERVER_NAME sarsrv01
USER_ID 501
SMB_NEGOTIATE AUTO_NEGOTIATE
SMB_VERSION SMB_3.02
SMB_SHARE_TYPE DISK
SIGNING_SUPPORTED TRUE
SIGNING_REQUIRED TRUE
EXTENDED_SECURITY_SUPPORTED TRUE
LARGE_FILE_SUPPORTED TRUE
CLIENT_REQUIRES_SIGNING TRUE
FILE_IDS_SUPPORTED TRUE
DFS_SUPPORTED TRUE
FILE_LEASING_SUPPORTED TRUE
MULTI_CREDIT_SUPPORTED TRUE
DIR_LEASING_SUPPORTED TRUE
ENCRYPTION_SUPPORTED TRUE
SIGNING_ON TRUE
other things I've noticed, that may not be related:
- when I click on the "default domain policy" in group policy editor, I receive this message:
The permissions for this GPO in the SYSVOL folder are inconsistent with those in Active Directory. It is recommended that these permisssions be consistent. To change the SYSVOL permissions to those in Active Directory, click OK.
- when I hover over the network icon in the tray, it shows the domain but says "No internet access", but there definitely is. Link teaming is turned on (done by previous admin). When I click on the icon, both "ethernet" and "ethernet 2" say limited access.
iMac Line (2012 and Later)