Solved

Using access based enumeration on shared folders.  Permissions required?

Posted on 2007-03-21
7
670 Views
Last Modified: 2008-01-09
I have a windows 2003 AD/domain environment.  The structure that I'm trying to create is to have a folder called "shared" with departmental directories underneath it.  For example \\server\shared\marketing, \\server\shared\finance, and \\server\shared\everyone.  The key is, I want to map all users to \\server\shared and have them only be able to "see" the folders underneath that they have access to - which I will grant via group objects.  For example a user in the finance group would be able to access \\server\shared\finance - but wouldn't even be able to see \\server\shared\marketing.

I've downloaded and enabled access based enumeration already on this folder.

I'm looking for the correct permission and share settings to make the above possible.

Your thoughts?

0
Comment
Question by:mikeshaver
7 Comments
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 18767506
have a check through this guide - these guys are pretty good at explaining most concepts
http://www.windowsnetworking.com/articles_tutorials/Implementing-Access-Based-Enumeration-Windows-Server-2003.html
0
 
LVL 51

Expert Comment

by:Netman66
ID: 18767724
You'd set it up as if you weren't using ABE.

Same share and ntfs permissions apply.  The only difference is they can only see what they have permissions to.

0
 
LVL 1

Author Comment

by:mikeshaver
ID: 18767804
Jay: Thanks, but that is exactly what I've already done.  

Netman:  I'm with you on this one, but I assume I don't have the share and security permissions correct.  

What is happening now is I have given rights to "read" at the \\server\shared\ folder to all my users.  This enables them to click on the \\server\shared folder without getting an "access denied" message.  However, the access is permeating down to all folders within the \\server\shared folder.  So if a user goes to \\server\shared folder, they see all the folders beneath it.  This is exactly what I do NOT want.

I don't really want to individually share out every subfolder in the \\server\shared folder...but is that what I need to do?  Should I share them, then enable ABE on every subfolder?

0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 19

Accepted Solution

by:
aissim earned 250 total points
ID: 18767925
You should go to each folder underneath the shared folder (finance, marketing, etc.) - go to the security tab, click the Advanced button, then uncheck the "Allow inheritable permissions from the parent to propogate to this object...". You'll be prompted to Copy or Remove the current, inherited, permissions - I recommend copying them and then back on the Security tab adjusting the ACL to your departmental needs.

At this point they won't be able to see folders they don't have access to. Good luck!
0
 
LVL 51

Expert Comment

by:Netman66
ID: 18770260
Share permissions = Authenticated Users - Full Control.
NTFS permissions = Administrators, SYSTEM = Full Control
                               Authenticated Users = Modify

Sub folders to be set as you normally would.

Since users need to be able to Modify their own stuff, then Inheritance should be allowed - just tighten up the security on the top level departmental folders so people can't delete things they shouldn't.

0
 
LVL 1

Author Comment

by:mikeshaver
ID: 18783381
Thanks guys.  I am off for a week but I will try this when I return and report back.

Mike
0
 
LVL 1

Author Comment

by:mikeshaver
ID: 19103213
Thanks everyone.

I ended up sharing out the "top level" called Shared to Authenticated users and the Administrators Group.  Then at each sub folder I set the permissions to whatever group required the access.
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now