Solved

Deny access to all data on server

Posted on 2014-01-08
3
391 Views
Last Modified: 2014-01-08
Hi

We have a new user that wants to be on our network (he doesn't work for my company) and we want him to be able to log into the domain and have internet access but no access at all to any of the data on our servers or any of the other PC's on the network. Is this possible to do?

We are running Windows Server SBS 2011.

Thanks in advance

Scott
0
Comment
Question by:cbapartnership
3 Comments
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 39764644
depends how you have the server setup.  if you have all your shares set for everyone:read/write or authenticated users:read/write then creating an account gives him access to everything.  if all your shares are secured logically by group, then create the account and dont put him in any group.  if he simply wants to connect his laptop to the network for internet, then there is no need to do that - he should be able to do so and get an ip address without you doing anything else.  

bottom line, it really depends how things are setup. without seeing your network, i cannot know because of all the variables involved.  if the network was setup properly it should be easy.  if it was setup to be secure, it could be more difficult but potentially easy.  and it depends which computer(s) he wnts to use (you could always create a local account on a specific computer or two).

can you ask the person who setup the network?

oh, and make sure you buy a client access license if you give him an account on the server.
0
 
LVL 53

Accepted Solution

by:
McKnife earned 500 total points
ID: 39765195
If you have many shares (no matter if at the servers or at other clients), and you don't want to worry about their security, I suggest to use a domain wide policy that sets the following: http://technet.microsoft.com/en-us/library/cc758316(v=ws.10).aspx ->Deny access to this computer from the network
->Add his user name there. Wherever the policy is in effect, he won't be able to access shares or shared printers, or other network functions.

Also important: in the user object modify one default setting: default is: he may logon to any computer. Set it to just his own.
That's all you need.
0
 

Author Closing Comment

by:cbapartnership
ID: 39765621
Thats great advice, many thanks for taking the time to answer.
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Using in-flight Wi-Fi when you travel? Business travelers beware! In-flight Wi-Fi networks could rip the door right off your digital privacy portal. That’s no joke either, as it might also provide a convenient entrance for bad threat actors.
Read about achieving the basic levels of HRIS security in the workplace.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now