Solved

Server 2003 Enterprise File Server and Workgroup access to shares...

Posted on 2009-04-13
9
666 Views
Last Modified: 2013-11-29
Well let me try to begin with...

I've come in to help a friend with their business network.  The previous admin left their place in a mess....  Essentially, they have a server which I had to clean and reinstall Windows Server 2003 Enterprise on.  They want to use this server as strictly a file server and repository for documents.

This is a very small office.  Currently 5 users with NO intent of growing beyond 10 people.  The group doesn't want Active Directory installed because they do not want to hire a dedicated admin.  They are using a WORKGROUP model.  (Yes, I've tried to talk them into using AD but they are not interested). 2003 Enterprise was a major un-needed upgrade but the last admin convinced them to get it.

Anyway, I re-installed the OS on this server, set it up as a file server and shared 3 folders out as requested.  All the house PC's are using Win XP Pro.  The house PC's can see the server - we'll call it:  NAME-FS  listed in network places and under Workgroup but cannot access it.  When they try they get an error saying that they don't have permission to log on to this device.

I went into the local security settings on the Server (which can see everybody in the workgroup by the way), and tried to add the accounts for the 2 house machines into the local security group list but received an error for that.

I can see the house PC's from the server, and can log into their machines with their local login permissions.  Keep in mind I'm dealing with local logins and no AD.  I'm trying to figure out why or what permissions I'm missing to prevent the house PC's from accessing the NAME-FS file server.  What am I missing?  I just need some ideas to get me rolling...
0
Comment
Question by:krazykc22
  • 5
  • 4
9 Comments
 

Author Comment

by:krazykc22
ID: 24134072
GREAT NEWS!
Solved the initial problem with being able to access shared folders.  All machines can see the folders now.  It was an issue with file and folder sharing not being selected on the server and windows firewall not allowing access through a TCP port to the server.  SOLVED....

NEW ISSSUE....  The clients want 3 shared folders on the D: drive of this new file server... I have those set up and people can see them.  The only problem is now that they want a seperate password on each shared folder.  They don't want to deal with permissions to do this, just a password access.  This is a workgroup internal to the organization where passwords on machines are NOT changed and not shared from person to person.   They want me to set up a different password to access each of the three shared folders on the D: drive.  I see no way to do this...any ideas...?
0
 
LVL 3

Accepted Solution

by:
RobDating earned 500 total points
ID: 24135303
You should be able to create 3 new users on the server (that do not exist on any of the client PC's) so for example:

Folder 1, create "user one" with a password
Folder 2, create "user two" with a password
Folder 3, create "user three" with a password

now on the sharing permissions for instance on folder 1 only allow "user 1" access. so when Bob who signs into his PC as Bob try's to access Folder 1 he has to enter "user one" as his user name along with the password to "user one's" account.
0
 

Author Comment

by:krazykc22
ID: 24135732
I think I understand.  So in essence, each person, when trying to access the share will have to enter the given password.  If the shares are already created and the workgroup computers have open access to them right now, how can I button down that open access to set this up correctly?  Do I have to delete the shares and start over?
0
Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

 
LVL 3

Expert Comment

by:RobDating
ID: 24135811
Right click on the folders in question go to Sharing and Security, Security tab.
Click Advanced and uncheck Allow inheritable permissions.....etc and check Replace permissions on all child ....etc
Remove all rights for all users other than the accounts (if any) you have just created (i.e. user one etc). and the Server Administrator account.

Test from all workstations that will be accessing the share to simulate realistic usage.
0
 
LVL 3

Expert Comment

by:RobDating
ID: 24135883
Sorry I forgot to ask how many people are accessing each share?
0
 

Author Comment

by:krazykc22
ID: 24137902
Currently there are only 3 people that could be accessing each share.  This could change but, if I'm understanding what you've said correctly, it won't matter how many they have so long as the password and account login for the share itself is known on the local server....

Well it might matter if there was a possibility of a lot of people accessing a share but there isn't in this case.  It won't get any higher than 5 or 6 people...ever...

What I'm thinking of doing is creating user acounts whose names match the name of the share and using the different passwords methods that way.  I think that may work.  I will have to try it..  Was there anything else you wanted me to know RobDating?
0
 
LVL 3

Expert Comment

by:RobDating
ID: 24141061
Nope I think you should be good.

Good luck
0
 

Author Closing Comment

by:krazykc22
ID: 31569716
RobDating,
Thank you for your patience on waiting for your points.  Well earned and deserved.  I have gotten so used to centralized mgmt of servers that I had forgotten some of the finer points of working with WORKGROUPS.  
Thank you for this solution.  YOU ROCK!
0
 
LVL 3

Expert Comment

by:RobDating
ID: 24306266
Not a problem I'm not a points junkie! just glad I could make someones life easier!
0

Featured Post

Active Directory Webinar

We all know we need to protect and secure our privileges, but where to start? Join Experts Exchange and ManageEngine on Tuesday, April 11, 2017 10:00 AM PDT to learn how to track and secure privileged users in Active Directory.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Outsource Your Fax Infrastructure to the Cloud (And come out looking like an IT Hero!) Relative to the many demands on today’s IT teams, spending capital, time and resources to maintain physical fax servers and infrastructure is not a high priority.
When you try to extract and to view the contents of a Microsoft Update Standalone Package (MSU) for Windows Vista, you cannot extract the files from the MSU. Here we are going to explain how to extract those hotfix details without using any third pa…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question