Solved

how to limit active dir user to access to one only folder with server 2003

Posted on 2011-03-25
8
370 Views
Last Modified: 2012-05-11
I have about ten users on a doamin and the server is maily just file and domain server. Im using logmein so as users can acess a shared folder. I have one user though whom i wish to restict to that folder only. I want it so that when he logs on to the server with his domain credentials through lmi. the desktop only shows that folder and no other. I dont want him to see any other folderr or drives --not c drive , not  program files etc -- just the one shared folder. Any ideas anyone and thanks in advance.
0
Comment
Question by:LeighJor
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 10

Assisted Solution

by:Muzafar Momin
Muzafar Momin earned 160 total points
ID: 35213571
you will need to setup seperate group policy for him for hidding the drive and folder and setup login script to map the only folder that you want him to see
0
 

Author Comment

by:LeighJor
ID: 35213664
whereabouts  can i set up group policy
0
 
LVL 32

Assisted Solution

by:nappy_d
nappy_d earned 160 total points
ID: 35213889
You can hide drives via a GPO but you cannot hide folders.

To restrict directory access, you need to use NTFS permissions.
0
MS Dynamics Made Instantly Simpler

Make Your Microsoft Dynamics Investment Count  & Drastically Decrease Training Time by Providing Intuitive Step-By-Step WalkThru Tutorials.

 

Author Comment

by:LeighJor
ID: 35213943
Thanks nappy_d but how and where do i find GPO. I can restrict his access to directories and folders ok it is mainly the c: drive i want to hide
0
 
LVL 11

Accepted Solution

by:
TheGorby earned 180 total points
ID: 35214936
Why do they need to actually log onto the server using LMI? Couldn't you just share the one folder he needs access to and map a drive to it on his own computer?
0
 

Author Comment

by:LeighJor
ID: 35220023
No TheGorby its a large resources folder shared by many, He has to logon remotely as do  10 others.unfortunately this guy only has to look at a folder and sudenly its sub folders disappear and reappear later in windows system folder or some other. He is a valuable intelligent employee with post grad quals but thats just tghe way it is.
0
 
LVL 11

Expert Comment

by:TheGorby
ID: 35222127
Ah yes, the classic "accidental drag-and-drop", always discovered when a user insists that several folders managed to delete themselves!

Ok so the user logs into the server from a remote site, using LMI. I assume you're using the Active Directory authentication integration with LMI? I'm not too familiar with that, when used that way are users then able to access domain resources as if they were logged onto the server with their own domain account?
0
 

Author Comment

by:LeighJor
ID: 35223885
They use AD authentication to logon to server. LMI permissions will not allow them to delete anything. Unfortunately though the can see folders on other drives c: and e: though they canot access them  and they can access system files etc on c:
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
A hard and fast method for reducing Active Directory Administrators members.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question