S
surfer10
Since Windows Server 2016 i cannot understand the logic anymore for folder shares..
Problem on servers with Windows Server 2016:
On the D drive on a Windows Server 2016 there are let's say a folder named folder1 and beneath it a folder named folder2.
folder2 is not shared yet and in the security tab so NTFS rights are assigned to several security groups. So far so good.
Now we share the folder and give everyone full rights on the share tab. Disable inheritance. When a user is trying to access the folder within a client machine in explorer \\servername\folder2 it can access the folder even when it is not in one of the groups in the security tab. How is this possible?
I discoverd that there is default a \\servername\users group in the security tab so i removed that group. Now the users cannot access folder2 anymore so the cause is that group (i cannot understand why a user is by default a member of the local users group....)
The problem is when i remove the local servername\user group: members of the seecurity groups which are in the security tab can also not access folder2 anymore from a othermachine in explorer, the system then gives a access deni.
So what is here the best solution without having to set rights on the share, so only on NTFS level?
freddie
Continue reading...
Problem on servers with Windows Server 2016:
On the D drive on a Windows Server 2016 there are let's say a folder named folder1 and beneath it a folder named folder2.
folder2 is not shared yet and in the security tab so NTFS rights are assigned to several security groups. So far so good.
Now we share the folder and give everyone full rights on the share tab. Disable inheritance. When a user is trying to access the folder within a client machine in explorer \\servername\folder2 it can access the folder even when it is not in one of the groups in the security tab. How is this possible?
I discoverd that there is default a \\servername\users group in the security tab so i removed that group. Now the users cannot access folder2 anymore so the cause is that group (i cannot understand why a user is by default a member of the local users group....)
The problem is when i remove the local servername\user group: members of the seecurity groups which are in the security tab can also not access folder2 anymore from a othermachine in explorer, the system then gives a access deni.
So what is here the best solution without having to set rights on the share, so only on NTFS level?
freddie
Continue reading...