When creating a top-level folder, you should set No Access to All Users. This follows the security principle of least privilege - by default, the folder should be restricted, and explicit access should be granted as needed. This prevents unauthorized access to new top-level folders.