Root Folder Settings
A folder setting on the site's root folder can cover every folder on the site, when the setting applies to subfolders. That makes the root the natural place to set up Malware Scanning or File Expiration for the whole site. Any user with the folder admin permission on the root folder can change or remove the setting, so a setting you count on can be turned off without you knowing. And the setting does not apply inside Workspaces, so files in a Workspace are ignored.
Two site settings change that. One allows only Site Administrators to change folder settings on the root folder. The other makes supported root folder settings apply in every Workspace.
Child Site Management Policies can put the same folder settings on every Child Site.
Restricting Root Folder Settings to Site Administrators
When the Restrict Root Folder Settings to Site Administrators setting is enabled, only Site Administrators can create, change, or delete a folder setting on the root folder, or turn a root folder setting off or back on for specific subfolders. The folder admin permission is often granted widely, and without this restriction any folder admin on the root folder could remove a setting that a Site Administrator put there.
Administration below the root is unchanged. Folder admins keep managing folder settings on the folders they administer.
Applying Root Folder Settings to All Workspaces
The Root Folder Settings Apply to All Workspaces setting makes supported root folder settings apply in every Workspace on the site, including Workspaces created later. Four folder settings are supported.
- File Expiration
- Limit Uploaded Files to Certain File Extensions
- Limit Uploaded Files to Regular Expression
- Malware Scanning
This setting requires Restrict Root Folder Settings to Site Administrators to be enabled first, and the restriction cannot be turned off while this setting is on.
Enforcement begins immediately. If File Expiration is set on the root folder and applies to subfolders, files start being deleted right away in every Workspace folder, except folders where File Expiration is set to Never delete files in this folder.
When Root Folder Settings Apply to All Workspaces is enabled, the supported root folder settings can be changed only in the default Workspace. A change there applies in every Workspace immediately. Workspace Administrators can see these settings but cannot change them.
You can turn this setting off later. The supported root folder settings then stop applying inside Workspaces, and each Workspace goes back to using only the folder settings set within it. Files that File Expiration already deleted are not restored.
Managing Root Folder Settings Across Child Sites
A Child Site Management Policy can create the four supported folder settings on the root folder of every Child Site it covers, and can turn on both settings on those sites. A folder setting managed by a policy is read-only on the Child Site for everyone, including the Child Site's own Site Administrators.
Seeing Who Can Change Each Folder Setting
The list of folder settings includes an optional Managed By column. For each folder setting, the column shows the lowest role that can change it, which is Folder Admin, Site Administrator, or Parent Site Administrator.
Higher roles can always change what lower roles can. A Parent Site Administrator outranks a Site Administrator, and a Site Administrator outranks a Folder Admin. A folder setting showing Folder Admin can be changed by all three roles, and one showing Parent Site Administrator can be changed only by a Parent Site Administrator.