Windows 2008 file sharing security


















When the arrow next to Password protected sharing is selected the options to enable or disable password protection sharing are provided. When enabled on workgroup servers, only users with user accounts and passwords on the server will be able to access shared files and folders. Shared folders can be configured using Windows Explorer, simply by navigating to the folder to be shared, right clicking on the folder and selecting Properties from the menu.

In the properties dialog, click on the Sharing tab to display and modify the current shared folder settings as illustrated in the following figure:. Within the sharing property panel, click on the Share Within this dialog, the users who may access this shared folder are specified. If file sharing has been restricted to users with local accounts and passwords, a list of users can be obtained by clicking on the down arrow. In this situation, select and add users, or select Everyone if access is to be made available to all users with local accounts:.

Once these settings are complete, click on the Share button to initiate the file sharing process. Once this initial phase of the share setup is complete a dialog will appear announcing this fact, listing the full Universal Naming Convention UNC path to the shared folder and providing the option to email users to notify them of this fact:.

Having specified which users will have access to the folder the next step is to enable the sharing of the folder, specify share permissions and configure a Share Name by which the folder will be referenced and accessed. In addition caching of shared files can be configured. Caching allows users to maintain local copies of shared files so that they can be accessed off-line for example when the server hosting the files is not available to the user's local system. With caching configured, local copies of shared files are stored on the user's local system so that they can be accessed without a connection to the server.

When a connection is re-established, any changes made to the local copy of the file are synchronized with the original copy on the server. In this dialog, set the Share this folder option to enable the sharing of the folder. Once this has been selected the Share name field and associated button will activate enabling a share name to be entered. By default the name of the folder being shared will be displayed, although this may be changed to another name if desired.

If the number of concurrent users accessing a shared folder is of concern, modify the number of simultaneous users accordingly. Enter optional comments about the share before clicking on Caching to configure the off-line file settings. This will invoke the Offline Settings dialog where a number of options are available including allowing each user to specify which files they would like to be able to access off-line, only having files that users actually access available off-line and disabling off-line sharing all together:.

The final step in the folder sharing setup is to click on Permissions to configure the share permissions , details of which are covered in a later section of this chapter. Windows Explorer provides an excellent mechanism for configuring shares on the local system. These settings are as follows:. Shared folders can be configured using Windows Explorer, simply by navigating to the folder to be shared, right clicking on the folder and selecting Properties from the menu.

In the properties dialog, click on the Sharing tab to display and modify the current shared folder settings as illustrated in the following figure:. Within the sharing property panel, click on the Share Within this dialog, the users who may access this shared folder are specified.

If file sharing has been restricted to users with local accounts and passwords, a list of users can be obtained by clicking on the down arrow. In this situation, select and add users, or select Everyone if access is to be made available to all users with local accounts:. Once these settings are complete, click on the Share button to initiate the file sharing process.

Once this initial phase of the share setup is complete a dialog will appear announcing this fact, listing the full Universal Naming Convention UNC path to the shared folder and providing the option to email users to notify them of this fact:.

Having specified which users will have access to the folder the next step is to enable the sharing of the folder, specify share permissions and configure a Share Name by which the folder will be referenced and accessed. In addition caching of shared files can be configured. Caching allows users to maintain local copies of shared files so that they can be accessed off-line for example when the server hosting the files is not available to the user's local system.

With caching configured, local copies of shared files are stored on the user's local system so that they can be accessed without a connection to the server. When a connection is re-established, any changes made to the local copy of the file are synchronized with the original copy on the server. To configure these settings, click on the Advanced Sharing button to display the following dialog:. In this dialog, set the Share this folder option to enable the sharing of the folder.

Once this has been selected the Share name field and associated button will activate enabling a share name to be entered. By default the name of the folder being shared will be displayed, although this may be changed to another name if desired.

If the number of concurrent users accessing a shared folder is of concern, modify the number of simultaneous users accordingly. Enter optional comments about the share before clicking on Caching to configure the off-line file settings. This will invoke the Offline Settings dialog where a number of options are available including allowing each user to specify which files they would like to be able to access off-line, only having files that users actually access available off-line and disabling off-line sharing altogether:.

The final step in the folder sharing setup is to click on Permissions to configure the share permissions, details of which are covered in a later section of this chapter. Windows Explorer provides an excellent mechanism for configuring shares on the local system. And for some reason I just kept missing that it was checked.

To continue this discussion, please ask a new question. Get answers from your peers along with millions of IT pros who visit Spiceworks. Best Answer. View this "Best Answer" in the replies below ». Popular Topics in Windows Server. Spiceworks Help Desk. The help desk software for IT. Track users' IT needs, easily, and with only the features you need. Learn More ». Sadly that check box is not working properly. If I manually adjust a file, then a user can access that file.

Privacy policy. SMB Encryption provides end-to-end encryption of SMB data and protects data from eavesdropping occurrences on untrusted networks. You can deploy SMB Encryption with minimal effort, but it may require small additional costs for specialized hardware or software. SMB Encryption can be configured on a per share basis or for the entire file server, and it can be enabled for a variety of scenarios where data traverses untrusted networks.

SMB Encryption should be considered for any scenario in which sensitive data needs to be protected from man-in-the-middle attacks. Possible scenarios include:. Windows will automatically negotiate this more advanced cipher method when connecting to another computer that supports it, and can also be mandated through Group Policy. Now data is encrypted before placement, leading to relatively minor performance degradation while adding AES and AES protected packet privacy.

This means that when using Storage Spaces Direct and SMB Direct, you can decide to encrypt east-west communications within the cluster itself for higher security.

You should note that there is a notable performance operating cost with any end-to-end encryption protection when compared to non-encrypted. You can enable SMB Encryption for the entire file server or only for specific file shares.



0コメント

  • 1000 / 1000