When you say everyone has administrator rights on the box. Did you add everyone into the administrators group? You should not give everyone administrator privilege. You should keep it at the least they need for their functions on the server. Assign the users to the domain users group. Create a group and add only those who need access to the resource then assign the group the appropriate (NTFS) permissions to the folder. If everyone has administrators right to the box they can always take over ownership of the folders and modify the permissions.