Solved

Deny access to all data on server

Posted on 2014-01-08
3
393 Views
Last Modified: 2014-01-08
Hi

We have a new user that wants to be on our network (he doesn't work for my company) and we want him to be able to log into the domain and have internet access but no access at all to any of the data on our servers or any of the other PC's on the network. Is this possible to do?

We are running Windows Server SBS 2011.

Thanks in advance

Scott
0
Comment
Question by:cbapartnership
3 Comments
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 39764644
depends how you have the server setup.  if you have all your shares set for everyone:read/write or authenticated users:read/write then creating an account gives him access to everything.  if all your shares are secured logically by group, then create the account and dont put him in any group.  if he simply wants to connect his laptop to the network for internet, then there is no need to do that - he should be able to do so and get an ip address without you doing anything else.  

bottom line, it really depends how things are setup. without seeing your network, i cannot know because of all the variables involved.  if the network was setup properly it should be easy.  if it was setup to be secure, it could be more difficult but potentially easy.  and it depends which computer(s) he wnts to use (you could always create a local account on a specific computer or two).

can you ask the person who setup the network?

oh, and make sure you buy a client access license if you give him an account on the server.
0
 
LVL 53

Accepted Solution

by:
McKnife earned 500 total points
ID: 39765195
If you have many shares (no matter if at the servers or at other clients), and you don't want to worry about their security, I suggest to use a domain wide policy that sets the following: http://technet.microsoft.com/en-us/library/cc758316(v=ws.10).aspx ->Deny access to this computer from the network
->Add his user name there. Wherever the policy is in effect, he won't be able to access shares or shared printers, or other network functions.

Also important: in the user object modify one default setting: default is: he may logon to any computer. Set it to just his own.
That's all you need.
0
 

Author Closing Comment

by:cbapartnership
ID: 39765621
Thats great advice, many thanks for taking the time to answer.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Cybersecurity has become the buzzword of recent years and years to come. The inventions of cloud infrastructure and the Internet of Things has made us question our online safety. Let us explore how cloud- enabled cybersecurity can help us with our b…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now