Advertisement

05.07.2008 at 09:15AM PDT, ID: 23383322
[x]
Attachment Details

Trying to achieve multi layer security on folders dependent on the source location of the user, rather then just the user.

Asked by WizPrang in Windows 2003 Server, Active Directory, Remote Desktop/Terminal Services

Tags: , , ,

We have 1 server, Windows 2003 Standard Edition with SP2.

This servers acts as domain controller, file server, printer server, application server, remote access/vpn server and a terminal server.

We have 2 hard drives on the server,
c:\  (system drive with applications that are installed on the server)
e:\  (company shared drive)

All users on the domain have access to the e:\ drive.

We would like to restrict this access so that only 2 folders are accessible within the e:\ drive
unc paths
\\servername\company share\index\folder1
\\servername\company share\index\folder2

Here's the twist, we only want restricted access when users are Terminally logged in. Whilst they are in the office they need access to all the files on the e:\ drive. This requirement is to prevent users from accessing sensitive data from home and potentially copying/printing that data.

We attempted this with 2 GPO's. The first was a loopback GPO set to merge and the 2nd was a User lockdown GPO attempting to prevent users access to these files. (if requested I can post the settings of the GPO).

The problem is, users are still able to brwose folders once they have explorer open by either clicking the Up folder button, or clicking the Folders button and then clicking the back button. Then they are able to access any folder they have permission for.

This idea was to try and mask files and folders making it extreamly difficult for a normal user to navigate their way to any where other then the 2 folders they should have access to.

Let me know if you require any more information,

thanks in advancedStart Free Trial
[+][-]05.07.2008 at 10:31AM PDT, ID: 21518575

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Windows 2003 Server, Active Directory, Remote Desktop/Terminal Services
Tags: Microsoft, Microsoft Windows Server 2003 Standard Edition, Service Pack 2, Group Policy Objects and Terminal Server.
Sign Up Now!
Solution Provided By: LauraEHunterMVP
Participating Experts: 1
Solution Grade: B
 
 
[+][-]06.26.2008 at 01:46AM PDT, ID: 21872831

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628