G
G
groovik2016-04-17 09:28:21
System administration
groovik, 2016-04-17 09:28:21

How to correctly combine access rights to shared folders?

Actually the question is how to properly assign access rights to shared folders? Each shared folder in Windows has two access options, using NTFS and SMB permissions SMB.SMB permissions only work when accessing a shared folder over the network and have no effect on the availability of a particular folder locally. NTFS permissions work both over the network and locally. There is a separate file server (Windows Server 2008 R2) with about 20 shared folders. Most of these are folders of different departments and divisions, groups for each department are created in AD, and full SMB and NTFS rights are set for each folder for the Domain Admins groups and for the group of the corresponding division. But recently, it has become very often necessary for certain employees to have access to the folders of other departments (they are not included in the group, respectively), and they are added by hand in both SMB and NTFS rights. Here also it would be desirable to learn, whether it makes sense to expose SMB permissions for All Full access, and to resolve access only NTFS? What does it threaten? Or how incompetent is that?
PS I'm sorry if I explain confusingly)

Answer the question

In order to leave comments, you need to log in

1 answer(s)
E
Eugene, 2016-04-17
@groovik

It has.
For greater security, you can put on network resources not everyone but authenticated users.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question