Welcome to ServerForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Share Permission vs NTFS

 
   Windows Server (Home) -> Windows Server Security RSS
Next:  Blocking Specific IP Addresses  
Author Message
Bad Beagle

External


Since: Oct 18, 2005
Posts: 44



(Msg. 1) Posted: Tue Jul 18, 2006 12:02 pm
Post subject: Share Permission vs NTFS
Archived from groups: microsoft>public>windows>server>security (more info?)

I have some remote work stations that have currently been added to our
domain. We cannot host their data on our servers so the remote work
stations have a data they share with other workstations in the office. It
is currently only locked down by share permissions. I have two issues:

1. NOw users on our lan can browse to these computers and see their data
2. Is there any advantage to go through the work of locking down with ntfs

 >> Stay informed about: Share Permission vs NTFS 
Back to top
Login to vote
Roger Abell [MVP]

External


Since: May 04, 2004
Posts: 559



(Msg. 2) Posted: Tue Jul 18, 2006 11:04 pm
Post subject: Re: Share Permission vs NTFS [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Opinions differ on this, and the answer to your item 2 can either fall out
from your use requirements, or your philosophy on things, or both.

Note that there are really three choices:
1. make the share permissions excessive and exert all control with
NTFS permissions only
2. make the NTFS permissions excessive and exert all control with
share permissions only
3. use both (effectively), whether necessary or not

There are many access control patterns that cannot be effected if one
uses only the share permissions with a sufficiently loose NTFS setting.
If the use cases do not force you to use of the NTFS permissions
then choices 1 and 2 could work.

I sort of see this like your having a car with an alarm system that you
can turn on and you also have one of those "club" steering-wheel locks.
So, do you use only the igition lock? or do you use the added protection?

The answer probably depends on the value of the car and how badly
you want to protect it, and also the difficulty of effecting the protection.
I see using both effectively (that is, to make minimally sufficient grants)
akin to turning on the car alarm - that is, it is simple (compare to using
the "club" which can be cumbersome).

So I guess you see where I stand, item 3, since it is a one-time action to
set up and results in your using what exists (as compared to voluntarily
disabling some of the available protection).


"Bad Beagle" <maxwelli RemoveThis @nospam.postalias> wrote in message
news:ebcdBRpqGHA.4760@TK2MSFTNGP03.phx.gbl...
>I have some remote work stations that have currently been added to our
>domain. We cannot host their data on our servers so the remote work
>stations have a data they share with other workstations in the office. It
>is currently only locked down by share permissions. I have two issues:
>
> 1. NOw users on our lan can browse to these computers and see their data
> 2. Is there any advantage to go through the work of locking down with
> ntfs
>

 >> Stay informed about: Share Permission vs NTFS 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
NTbackup and admin share - Hi Everyone ! I have installed 2 new WIN2003 serveur on our network.... And I want to configure backup (ntbackup) on one WIN2003 server to backup the data on the other WIN2003 server... But when I browse (in ntbackup) to obtain the server list and the..

How can you change access permissions to global system obj.. - I was investigating why isobuster wouldn't browse CD drives under a limited-user account, and auditing object access failures revealed nothing in the event log until I turned on "Audit the access of global system objects" in security options. T...

Permission for Shares - I have setup home directories for all of our users. I have one user that needs access to multiple home directories for our production lines. They place files in there for the users to access. My question is: Can i map a drive letter for him, but only..

Lost permissions - Here's an interesting one. We use a batch file called cegetter to download virus definitions from Symantec. Occassionally, the navup8.exe file (which updates the defs) does not get deleted by the batch file, and this prevents the definitions from updatin...

Directory Permissions - I am recreating groups on a win2k server. We transferred the files over from a netware 5.0 server. I created the share data, then under there are various folders and files. I granted a group access to a folder burried deep in the directory structure, but...
   Windows Server (Home) -> Windows Server Security All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]