Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

I would like to restrict certain users from accessing a shared folder when not at their own workstation.

Posted on 2010-11-26
5
995 Views
Last Modified: 2012-05-10
I want to be able to restrict users access to certain folders, when they are not at their own workstation. This is to prohibit them from trying to access sensitive information from these folders, on workstations at other locations.

Thanks in advance

jt.
0
Comment
Question by:ICGIT
  • 3
  • 2
5 Comments
 
LVL 5

Expert Comment

by:Seth_McCauley
ID: 34219660
I do not believe this is possible with the built-in security of Windows file shares, although there may be 3rd party security software that adds this feature.

Are all your file shares on one server? If not, you could restrict access to this file server to specific computers using the built-in firewall. The main catch with this is that it require the department accessing the share to be on it's own IP range or subnet. I know this isn't the most convenient method, but it may be your only option.

Hope this helps.
0
 

Author Comment

by:ICGIT
ID: 34241263
Hi Seth,

All shared folders are on one file server. I was thinking of assigning a group of machines acces to a folder but am not sure that is actually possible, as you already are implying. Can a user have cedrtain rights on one workstation which they don't have on others maybe??

thanks,

jt.
0
 
LVL 5

Accepted Solution

by:
Seth_McCauley earned 500 total points
ID: 34248813
No, not that I know of. I did some research and really racked my brain on this, and I do not believe there is a way to set NTFS or share-level permissions that are specific to a computer or group of computers. I can definately see where this would be useful behavior, however it just doesn't seem to exist. The best I've come up with are a few (somewhat messy) workarounds...

Create multiple network accounts for these users. The users would have one account that has access to the share (let's call it the "secure account" for now) and one that does not. You could then restrict the secure account to only logging into specific computers by using Active Directory user account settings to whitelist computers ("Logon To..."), or Group Policy to blacklist computers ("Deny Logon Locally"). Group Policy will be more convienient, because the AD method will require an up-to-date list of computer names and GP will just be applied to specific OUs.
Use something other than Windows file sharing. For example, you could setup a FTP/SFTP share for this sensitive data, then restrict FTP access to a specific IP range. 3rd Party FTP software might even let you specify IP ranges restrictions for each share.
Build seperate file servers for any data that can't leave a department. This server could be accessed by specific domain users, but only on the computers in that department. All other workstations would then be blocked in the Windows firewall on that server. In order to create that firewall rule, these computers would ideally be on a different subnet than the other workstations. However, given the confidentiality concerns with this data, putting these computers on a separate subnet would be a good idea regardless.
I know these are the solutions you were hoping for, but this at least gives you some alternatives to not restricting by computer at all.
0
 
LVL 5

Expert Comment

by:Seth_McCauley
ID: 34251412
Glad I could help!
0
 

Author Comment

by:ICGIT
ID: 34251895
Thanks Bro. I'm going with the eclusive workstations on a different subnet.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

792 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question