Link to home
Start Free TrialLog in
Avatar of Gavin75
Gavin75Flag for Australia

asked on

Does Windows 2016 Server block non-domain computers accessing shared folders?

Does Windows 2016 Server block non-domain computers from accessing shared folders by default or is additional configuration required?
ASKER CERTIFIED SOLUTION
Avatar of Cliff Galiher
Cliff Galiher
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of timgreen7077
timgreen7077

Yes they are blocked by default. it doesn't matter if they are domains joined or not. you must be granted permissions to access shared folders.
Avatar of Gavin75

ASKER

Hi, there seems to be a bit of a misunderstanding: I understand that access to files and folders can be controlled at a User level but what I don't want are Users connecting computers to the network, which are not joined to the domain and being able to access shared folders using their Domain login credentials. I realise there are various ways to control access to the network at a layer 2 level using switches etc. but I am interested in how Windows 2016 Server reacts to non-domain computers trying to access domain resources, in particular, shared folders. Thanks for your input.
Hi, there seems to be a bit of a misunderstanding: I understand that access to files and folders can be controlled at a User level but what I don't want are Users connecting computers to the network, which are not joined to the domain and being able to access shared folders using their Domain login credentials.

Wow, yeah I'll bet there is a bit of a misunderstanding because you've asked a completely different question :) If you're looking after a Windows server solution I would try looking at Dynamic Access Control (DAC) and setting up an access rule that requires a user and device claim for access. This will require a client OS of Windows 8 or higher to support device claims. Otherwise you're going to need to look at a network solution.
Avatar of Gavin75

ASKER

It was definitely the same question, just elaborated on but I appreciate your input. I’ll have a closer look at your suggestion and the related GPO settings. Thanks
No comment has been added to this question in more than 21 days, so it is now classified as abandoned.

I have recommended this question be closed as follows:

Accept: Cliff Galiher (https:#a42473474)

If you feel this question should be closed differently, post an objection and the moderators will review all objections and close it as they feel fit. If no one objects, this question will be closed automatically the way described above.

seth2740
Experts-Exchange Cleanup Volunteer