Rob Golding

Technology Consultant
  • rss
  • Home
  • About
  • RSS
  • Contact

Configuring Share Permissions

September 19, 2007

When I was “starting out” in the IT field, I always used to setup shared folders in a certain way - I would set the Share Permissions to Everyone - Full Control, then use the NTFS Permissions to control access to the share - which always seemed like the most simple and secure way to do things.

Share PermissionsHowever, when talking to the Network Administrator at my college, I was informed that setting the “Full Control” item was extremely bad from a security standpoint, as it allowed any user in the specified group (in this case, Everyone) - to change options in regard to the share configuration - like the permissions themselves.

So from this point on, I changed my habits to setting the Share Permissions to Authenticated Users - Change, and then using the NTFS permissions, as before, to control access to the data. Today, however, I decided to do my homework.

A quote from this article states the following:

“The recommended permissions have been tested, and work correctly; but there are alternative approaches. For example, some experienced administrators prefer always to set share permissions to Full Control for Everyone, and to rely entirely on NTFS permissions to restrict access.”

To me, it sounds like Microsoft have no reservations about using this method, and certainly don’t mention any security risks at all. So, hearing anyone else’s opinion would be very useful, but seeing as it works well - for now I will carry on using the Authenticated Users - Change permission object.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Slashdot
  • StumbleUpon
  • Technorati
Categories
Technology, Windows Server
Comments rss
Comments rss
Trackback
Trackback

« phpBB3 WSOD (White Screen of Death) Network Redesign »

Leave a comment

You can use these tags : <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

Oh no, I cannot read this. Please, generate a

Pages

  • About
  • RSS

Navigation

  • Active Directory
  • Exchange
  • Home Network
  • Life
  • Linux
  • Technology
  • Virtualization
  • VMware
  • Web Development
  • Windows Server

Archives

  • July 2008
  • April 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007

Recent Posts

  • Using Locally-Attached Network Printers with Terminal Services
  • Cacti and Network Weathermap
  • Restoring the Separate _msdcs Zone
  • Roadwarrior with IPCop & OpenVPN
  • New IPCop Firewall

Weathermap

rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox