Solved

Folder Share Permissions BEST PRACTICES

Posted on 2010-08-12
2
898 Views
Last Modified: 2012-05-10
Its been a while since I studied this topic but I remember there is a BEST PRACTICES way of setting up a new share on a folder in Windows Server 2003.
When you set up a Folder for sharing the first time, there is a PERMISSIONS Button on the SHARING Tab. When you press the button it opes a window with Everyone in the top group with READ rights, by default I believe.

Then there is the SECURITY Tab. WHen you open that window it has the Regular Security settings window with SYSTEM and OWNER etc. with a long list of rights that can assigned to the selected user or group.

The question is then...Should the PERMISSIONS button be used at all in a normal Windows 2003 Active Directory Domain? And if so...how? IE: Remove EVERYONE ?

Then ad the Everyone Item back in Under the SECURITY Tab? And others as appropriate?

0
Comment
Question by:NaplesFLDave
2 Comments
 
LVL 15

Accepted Solution

by:
JBond2010 earned 250 total points
Comment Utility
As a best practice, it is most efficient to configure share permissions with Authenticated Users having Full Control access. Then, the NTFS permissions should configure each group with standard permissions. This provides excellent security for local and network access to the resource. It also provides excellent protection of the resource for when it is backed up and when the resource name is changed or relocated. As I said earlier, the NTFS permissions will protect the resource even if the share permissions are set to Full Control access.
0
 
LVL 2

Expert Comment

by:itmaximum
Comment Utility
also good to remember that microsoft servers use MOST RESTRICTIVE as its priority, so when changing security settings make sure they match your share permissions, if you dont you will have an access denied issue without realizing it.

(simply if you have authorized users full control in permissions and then change the folder security to a specific security group, only the members of that group will have access)
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now