Solved

Setup FTP user windows server 2008

Posted on 2015-02-21
3
359 Views
Last Modified: 2015-03-19
Hello ,

I have setup  my FTP on my windows server 2008.

I have created a user account to access this FTP, let's call it FTP_USER. Everything is working good.

How can I restrict this account FTP_USER to only be able to access the FTP and nothing else. I don't want this account to login to my server or anything else.

Thanks
0
Comment
Question by:arnololo123
3 Comments
 
LVL 9

Expert Comment

by:Benjamin MOREAU
ID: 40624598
I never use Microsoft FTP (personal choice), but I use the Free FTP Server "Filezilla server". With this solution, you can use accounts created on filezilla server and not on windows.

Maybe somebody have a solution to disable logon with windows account without to disable ftp access... but i don't know how to do that... (maybe with local security - GPEDIT.msc).
0
 

Author Comment

by:arnololo123
ID: 40673078
Thanks but this does not resolve my problem
0
 
LVL 28

Accepted Solution

by:
Bill Bach earned 500 total points
ID: 40676810
I would echo Benjamin's comments.  The Microsoft FTP server does have some issues, and I also use Filezilla to avoid these security issues, as well as provide for download and upload "speed limits" to prevent random people from impacting my Internet uplink performance.  You can see this if you do a web search for "free ftp server comparison" -- even though Microsoft's ftp service is free, it is RARELT (or NEVER) mentioned in any of these comparisons or reviews.

If your ONLY option was the Windows FTP service, then you should know that the Microsoft security is handled by exclusion, not inclusion.  In other words, rights are subtractive, not additive.  First, make sure that the user is NOT a member of any groups -- it should be a stand-alone account.  Then, you want to explicitly define NO rights for this user to the root of each volume.  Then, explicitly assign rights to the FTP folder(s) as needed.  By default, the user should not have the Log On Locally right, but you may wish to check this (in gpmc.msc) and exclude this right, too.  This will help prevent the login from being able to sign onto the server console itself, too.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Join & Write a Comment

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup". After a while, you have entered a loop for Auto repair which does not fix anything and you will be in a  panic as all your work w…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now