How to Fix SharePoint and Local File Server Permission Inheritance
Question details
Users need to resolve an issue where files uploaded to SharePoint by remote users fail to inherit the correct NTFS permissions on the local file server, leading to access issues and duplicate files.

- Product
- SharePoint and Windows Server
- Device & OS
- not provided
- Scenario
- Remote staff are uploading files to a hybrid SharePoint environment that is synchronized with a local file server.
- Observed behavior
- Files uploaded via browser do not inherit the required local file-server permissions. Additionally, the synchronization process creates duplicate Word and Excel files.
Ensure you have administrator access to both your Microsoft 365 Admin Center and the local Windows Server environment before modifying NTFS permissions or synchronization settings.
Review User Mapping and NTFS Inheritance Settings
Verify the identity mapping between SharePoint cloud accounts and local file-server accounts to ensure permissions translate correctly during synchronization.
In a hybrid environment, files uploaded to SharePoint by remote users rely on Azure AD Connect (or similar tools) to map cloud identities to local Active Directory accounts. If this mapping fails, files will not inherit the correct local NTFS permissions.
Open your local Windows Server environment, right-click the synchronized folder, select 'Properties', and navigate to the 'Security' tab. Click 'Advanced' and ensure that inheritance is enabled for the parent folder.
Work with your IT provider or Microsoft 365 administrator to confirm that the remote users' email addresses in SharePoint correctly map to their local Active Directory profiles.
Once the mapping and NTFS inheritance settings are confirmed, restart the OneDrive sync client on the server to apply the updated configurations to new uploads.

Apply a PowerShell Script for Newly Created Files
Use an automated PowerShell script to force correct permission inheritance on newly synchronized files as a temporary workaround.
Try WPS Office for Seamless Cloud Collaboration
If you are experiencing persistent synchronization conflicts, permission errors, and duplicate files with Microsoft Office and complex local servers, consider WPS Office as a reliable alternative. It provides native, hassle-free cloud storage and is completely compatible with Microsoft Office formats.
- 1. Download WPS Office: Visit the official WPS website and download the free WPS Office suite for your operating system.
- 2. Activate WPS Cloud: Sign in with your email to activate your free WPS Cloud storage space, allowing you to bypass local server sync issues.
- 3. Collaborate Remotely: Save and share documents directly through WPS Cloud. Remote team members can edit files without generating duplicates or running into NTFS permission barriers.

Frequently Asked Questions
Why does OneDrive synchronization create duplicate Word and Excel files?
Duplicate files often occur due to synchronization conflicts. This happens when multiple users edit a file simultaneously, or when local file server permissions prevent the sync client from saving changes over the original file, forcing it to create a duplicate copy.
How does user mapping affect SharePoint hybrid environments?
User mapping links a user's cloud identity in Microsoft 365 to their local Active Directory account. If this link is broken or misconfigured, files uploaded via SharePoint will not be recognized by the local server, resulting in a failure to inherit proper NTFS permissions.
Can I force NTFS permission inheritance on an existing folder?
Yes. Right-click the folder, go to Properties, select the Security tab, and click Advanced. Check the box that says 'Replace all child object permission entries with inheritable permission entries from this object' and click Apply.
Is a PowerShell script a permanent fix for permission inheritance issues?
No. While a PowerShell script using 'icacls' can temporarily reset permissions for newly created files, the best long-term solution is to properly configure your Active Directory identity mapping and Azure AD Connect.




