Computer: Active Directory and Share Permissions
The Place For Free Online Training Courses Improve Your Career Prospects Skip to primary content Skip to secondary content Home Microsoft Accreditation Basic IT Traveling Business Tutorials Website Building Career Tutor Post nonparticipating Network Drives -?+ Shared Folders and UNC Paths Sharing folders allows users to access resources on other machines on the network. Both machines must have file and print services for Microsoft Networks Installed to allow shared folders to be accessed. Only folders, and not individual files, may be shared.
Any files that need to be shared should be placed within a shared folder. SE the buttons below to navigate through the lesson A shared folder is accessed through its UNC Path. This has the general form of Servershare. Serverpublic This command would open a shared folder called “public” held on a computer called “server”. This address also adheres to the UNC path formula of where the computer name is substituted by the IP address of the server Share Permissions Shared Folders and UNC Bathysphere folder access can be restricted by using Share Permissions.
For example, John might be able to read the accounts folder whilst David might be denied access. Share permissions can also be applied to groups. If a user is a member of more than one group then he/she will get the cumulative permissions of all groups. However, the DENY permission will always take precedence. A user or group can be either allowed or denied the following permissions to a folder. READ: Allows a user to view the contents of a folder, and execute files within the folder CHANGE: Allows a user the Read permission, as well as allowing him/her to modify the contents of the folder.
FULL CONTROL: Allows a user the Read and Change Permission as well as changing file permissions and ownership. CAUTION: Shared Folder Permissions only apply to folders being accessed over the network and not for local logins. To restrict access for local logins use ANTS permissions. Multiple Share Permissions have different permissions. Managers – Read Permission Accounts – Change Permission If Fred is a member of both Managers and Accounts, Fred would have both Read and Change Permission. Caution has to be taken when using multiple groups and the DENY permission.
The DENY permission will always take precedence. As noted before if a user is a member of more than one group then he will get permissions of both groups. Managers -Full Control Permission Accounts – Deny Read Permission If Fred is a member of both Managers and Accounts, Fred would be denied access. Administrative Shares Windows 2000/XP and 2003 have a number of hidden shares which are created by default when the operating system is installed. These shares are known as administrative shares.
Administrative shares are only accessible by the administrator and are hidden when browsing the network. The following are the default administrative shares on a Windows 2000/XP and 2003 computer. $ Each drive on the computer is shared as $ example to access drive C: on server o would use C$ admit$ The windows folder is shared as admit$ PC$ The PC share is used by the Windows File Replication Service. Sharing a Folder Before sharing specific folders on a Windows XP Professional machine, simple file sharing needs to be disabled.
Click on Tools. Select Folder Options. Select the View tab. Unchecked the Use simple file sharing option. Click on K to close the Folder Options dialog box. Right-click on the folder you wish to share. Select Sharing and Security… Click on Share this folder. A share name is automatically given, however this can be changed here. A comment can also be added if needed. A user limit for the share can also be specified. Remember that Windows XP can only support 10 simultaneous connections. To configure share permissions click on Permissions.
Every folder has an Access Control List (CAL) which specifies which users and groups have access to it. Currently the Everyone group has Read permission to the share. Click on Remove to remove the Everyone Group. N. B. You should never deny the Everyone group access since every user on the system would be denied access no matter what other groups they were a member of. It is safer to simply remove the everyone group from the list. Click on Add to add a new user. Enter the name or names of the users and groups that you wish to add to the Access Control List. Jackson;Pauline potter” will add the two users Jackson and Pauline Potter. Click on K to accept. The users have now been added to the Access Control List. Currently Pauline has Read access to the share. Click on Ross Jackson to configure permissions. Select Allow Full Control to give Ross Jackson full control over the shared folder. Full Control will automatically enable Change and Read. Click on K to accept. The shared folder is displayed with a hand underneath it .. And can be accessed over the network by using the UNC path \TonySerrate.
Shared Folders can also be created and managed through the Shared Folders management console in System Tools. Click on Start. Right-click on My Computer. Select Manage. The Computer Management Console will appear. Expand Shared Folders. From here you can create shares, view and disconnect any current sessions and view or disconnect any open files. Click on Shares to create a new share. All the current shares are displayed. To create a new share right-click on the empty space in the share list. Select New File Share. Type or browse for the folder you wish to share into the Folder to share box.
Get access to
Guarantee No Hidden