Multi-User Access: Verifying Folder Sharing & Network Permissions

Multi-user access in QuickBooks Desktop requires that Windows share permissions and NTFS file system security permissions work together without conflict. If permissions are misconfigured, client workstations cannot read or write to the shared company file directory, triggering errors like H202, 6000-series lockouts, or “Permission Denied” notices. To ensure smooth multi-user access, you must grant Full Control under both Advanced Sharing and NTFS Security to the dedicated QBDataServiceUser, the Windows system accounts, and the staff members accessing the file.

Fast-Fix: The 45-Second Solution

To verify folder permissions, right-click the company folder > Properties > Sharing > Advanced Sharing > Permissions and grant Everyone “Full Control.” Next, go to the Security tab and grant Full Control to QBDataServiceUserXX, SYSTEM, and your QuickBooks users. Misconfigured security access blocks multi-user handshakes. Matching both Share and NTFS permissions to Full Control resolves file-sharing blocks immediately.

Quick Status & Triage Snapshot

  • Data Risk Tier: Low to Medium. Incorrect permissions block file access; setting permissions too broadly can introduce security risks, but will not corrupt financial data tables.
  • Multi-User Impact: Total. If network or NTFS permissions are missing, workstations cannot open or edit company files across the network.
  • Common Trigger: Moving company files to a new drive, Windows operating system upgrades resetting folder inheritance, or creating a new Windows user who was not added to the local sharing group.
  • Estimated Fix Time: 10 to 15 minutes.

Diagnostic Flowchart: Folder Permissions Decision Path

[Start: Workstation cannot open shared file / Permission Denied]
   │
   ▼
Inspect the parent folder on the host server:
Right-click folder > Properties > Sharing tab > Advanced Sharing > Permissions.
Is "Everyone" (or your QB user group) granted Full Control?
   ├─► No ──► Check "Allow" for Full Control, Change, and Read. Apply.
   └─► Yes ─► Share permissions are correct. Inspect NTFS permissions.
                 │
                 ▼
              Switch to the Security tab on the folder properties.
              Are QBDataServiceUserXX, SYSTEM, and Users listed with Full Control?
                 ├─► No ──► Add missing users/groups and grant Full Control.
                 └─► Yes ─► Check permission inheritance.
                               │
                               ▼
                            Are subfiles (.ND, .TLG, .QBW) inheriting permissions?
                               ├─► No ──► Click Advanced > "Replace all child object permissions."
                               └─► Yes ─► Permissions verified. Check Windows Firewall ports.

Is Your Data at Risk?

Your financial data is not corrupted by a permission lockout. Windows is doing what it is designed to do: blocking access to files when credentials cannot be verified.

However, operational data risk increases if NTFS permissions are configured with “Read” access only. If a user opens a file with partial permissions, QuickBooks cannot write transaction log entries or update the .ND file. The application will abort transactions abruptly, potentially causing database indexing problems. Always verify that all authorized QuickBooks users have full read, write, and modify permissions.

Technical Anatomy: Share Permissions vs. NTFS Permissions

Windows uses a dual-layer security model to protect shared files:

  1. Share Permissions (The Network Gate): Governs access across the network via the Server Message Block (SMB) protocol. When a client workstation navigates to \\Server\QBData, Windows evaluates the Share Permissions first. If this layer is set to “Read Only,” no user can write data to the folder from across the network, regardless of their individual user account rights.
  2. NTFS Security Permissions (The Local Drive Gate): Governs access at the physical file system level on the host hard drive. This layer dictates what individual local accounts and service daemons (specifically the QBDataServiceUserXX account created by the Database Server Manager) can do with the files.

The Golden Rule of Windows Permissions: When Share Permissions and NTFS Permissions overlap, Windows enforces the most restrictive permission. If Share Permissions grant “Full Control” but NTFS grants only “Read,” the effective permission is Read-Only, and QuickBooks multi-user access fails. Both layers must permit full read/write/modify access.

Differential Diagnosis: Don’t Confuse This With…

  • QuickBooks Error H202 (Firewall block): The user has full permission to read the folder, but Windows Firewall drops the TCP packet trying to reach port 8019.
  • QuickBooks Error 6189, 816: Permissions are set correctly, but an orphaned background process has placed an exclusive file lock on the .qbw file.
  • QuickBooks Error 6175, 0: Permissions are correct, but the database manager service on the server is stopped and cannot mount the database.

Step-by-Step Permission Verification Guide

Execute these steps on the host server or computer physically storing the company files.

Step 1: Set Advanced Sharing Permissions

Do not use the basic Windows “Share” button, as it often sets restrictive defaults. Use Advanced Sharing instead.

  1. Locate the folder holding your company file (e.g., C:\QuickBooksData or D:\QBShare).
  2. Right-click the folder and select Properties.
  3. Select the Sharing tab, then click Advanced Sharing.
  4. Check the box for Share this folder.
  5. Click the Permissions button.
  6. Under “Group or user names,” select Everyone (or your designated Active Directory accounting security group):
    • Under the Allow column, check Full Control, Change, and Read.
  7. Click Apply, then click OK. Do not close the main Properties window yet.

Step 2: Configure NTFS Security Permissions

Now configure the file system permissions on the same folder.

  1. In the folder Properties window, click the Security tab.
  2. Click the Edit… button to adjust permissions.
  3. Review the list of group and user names. The following accounts must be present:
    • SYSTEM
    • Administrators
    • Users (or the specific local/domain users needing access)
    • QBDataServiceUserXX (where XX matches your version year, e.g., QBDataServiceUser36 for 2026)
  4. If an account is missing, click Add:
    • Type the missing user or group name into the text box.
    • Click Check Names, then click OK.
  5. Highlight each user/group one by one, and check the box for Full Control under the Allow column.
  6. Click Apply, then click OK.

Step 3: Enforce Permission Inheritance on Child Objects

Sometimes parent folder permissions are configured correctly, but individual .qbw, .ND, or .TLG files inside retain older, restrictive permissions.

  1. On the Security tab of the folder Properties, click Advanced near the bottom.
  2. At the bottom of the Advanced Security Settings window, check the box:
    “Replace all child object permission entries with inheritable permission entries from this object.”
  3. Click Apply.
  4. A Windows Security warning will appear asking to confirm replacing permissions on all subfiles; click Yes.
  5. Click OK to close all windows.

Step 4: Verify Network Share Access from a Workstation

Test that your adjustments work across the local area network.

  1. Move to a client workstation.
  2. Press Windows Key + R, type the UNC path to the server folder (e.g., \\Server-PC\QuickBooksData), and press Enter.
  3. In the folder that opens, right-click an empty space, select New > Text Document.
    • If the text file is created without error, your share and NTFS permissions have full read/write capabilities. Right-click and delete the test text file.
    • If Windows displays “Destination Folder Access Denied” or prompts for administrative credentials, permission restrictions remain on the host. Re-check Steps 1 and 2.
  4. Launch QuickBooks Desktop and open the company file over the network.

Hard Stop: When to Call an Expert

Escalate to a systems administrator or network engineer if:

  • The company file is stored on a specialized Storage Area Network (SAN) or non-Windows network storage device with proprietary Access Control Lists (ACLs) that do not support standard Windows security identifiers (SIDs).
  • Active Directory Group Policy Objects (GPOs) continuously reset the security permissions on the shared drive during daily domain refreshes.
  • The local Windows Security Accounts Manager (SAM) database on the host is corrupted, preventing the creation or validation of the QBDataServiceUser account.

If folder permissions are verified but file access issues persist, explore these related topics:

Closing the Books

Folder sharing in QuickBooks requires balance: your accounting files must be protected from unauthorized outside access while remaining fully accessible to the services and staff who rely on them. By aligning both Share permissions and NTFS security permissions to Full Control and applying those rights down to every subfile in the directory, you eliminate access roadblocks and ensure your multi-user environment operates without interruption.