Click here to get back home

Windows 2003 Shared Drive Permissions

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Windows 2003 Shared Drive Permissions moncho 10-09-2007
Posted by moncho on October 9, 2007, 7:14 am
Please log in for more thread options
Windows 2003 Std as DC
Windows 2003 Std as File Server
Windows 2003 Std as TS Server

FS has a shared drive of F:\SD
TS needs Full Control of F:\SD\DATA$ for
the main business application

All internal and external users log on to
TS server to access the business application.
The TS is using UNC Pathing \FS\SD\DATA$.

What I would like to do is setup the shared
drive and NTFS permissions so that all
authenticated users have R+W access but
ONLY from the TS server and no access from their
local workstation.

I hope that came out correctly and is possible.

I am thinking that I should add all computer
accounts, except TS computer, to a Security Group
and then deny access for that Security Group.

Am I correct in my thinking on this?

Thanks.

moncho

Posted by DaveMo on October 10, 2007, 9:26 am
Please log in for more thread options
> Windows 2003 Std as DC
> Windows 2003 Std as File Server
> Windows 2003 Std as TS Server
>
> FS has a shared drive of F:\SD
> TS needs Full Control of F:\SD\DATA$ for
> the main business application
>
> All internal and external users log on to
> TS server to access the business application.
> The TS is using UNC Pathing \FS\SD\DATA$.
>
> What I would like to do is setup the shared
> drive and NTFS permissions so that all
> authenticated users have R+W access but
> ONLY from the TS server and no access from their
> local workstation.
>
> I hope that came out correctly and is possible.
>
> I am thinking that I should add all computer
> accounts, except TS computer, to a Security Group
> and then deny access for that Security Group.
>
> Am I correct in my thinking on this?
>
> Thanks.
>
> moncho

Hello Moncho,

No, there's no way you can do this through the ACL on the file share.
When the users log on to the TS and then connect to the file server
the authentication will be as the user. The fact that they came
through the TS box is irrelevant as far as the ACL/FileShare security
is concerned. It's very easy to solve this challenge using IPSEC,
however. A simple policy that only allows access from the TS box
should do the trick.

HTH,
Dave


Posted by moncho on October 11, 2007, 7:10 am
Please log in for more thread options
DaveMo wrote:
>> Windows 2003 Std as DC
>> Windows 2003 Std as File Server
>> Windows 2003 Std as TS Server
>>
>> FS has a shared drive of F:\SD
>> TS needs Full Control of F:\SD\DATA$ for
>> the main business application
>>
>> All internal and external users log on to
>> TS server to access the business application.
>> The TS is using UNC Pathing \FS\SD\DATA$.
>>
>> What I would like to do is setup the shared
>> drive and NTFS permissions so that all
>> authenticated users have R+W access but
>> ONLY from the TS server and no access from their
>> local workstation.
>>
>> I hope that came out correctly and is possible.
>>
>> I am thinking that I should add all computer
>> accounts, except TS computer, to a Security Group
>> and then deny access for that Security Group.
>>
>> Am I correct in my thinking on this?
>>
>> Thanks.
>>
>> moncho
>
> Hello Moncho,
>
> No, there's no way you can do this through the ACL on the file share.
> When the users log on to the TS and then connect to the file server
> the authentication will be as the user. The fact that they came
> through the TS box is irrelevant as far as the ACL/FileShare security
> is concerned. It's very easy to solve this challenge using IPSEC,
> however. A simple policy that only allows access from the TS box
> should do the trick.

Thanks Dave.

I will look into this.

moncho

Similar ThreadsPosted
Shared drive VS Security September 19, 2005, 4:22 pm
c:\ drive permissions June 23, 2005, 5:10 pm
Shared folder permissions August 18, 2006, 3:20 pm
Windows 2003 R2 delegated permissions are not available for some users in an OU January 2, 2007, 12:15 pm
Windows Server 2003 - Services Permissions Issue August 29, 2005, 1:28 pm
Windows 2003 permissions and Process Monitor outpu March 9, 2007, 6:35 am
Windows 2003 Problem with Group Policy for Services Startup and Permissions April 27, 2006, 7:27 am
Windows service denied access to mapped drive May 4, 2007, 7:06 am
Shared SSL on my WIn 2003 Server November 2, 2007, 9:23 am
listing of shared folders in 2003 based domain February 10, 2008, 6:17 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap