SlideShare ist ein Scribd-Unternehmen logo
1 von 38
Module 4:
Administering File
   Resources
Overview

     Using NTFS Permissions
     How Windows 2003 Applies NTFS Permissions
     Assigning NTFS Permissions
     Copying and Moving Files and Folders
     Sharing Resources
     Creating Shared Folders
     NTFS Permissions and Shared Folders
     Troubleshooting Access Problems
     Best Practices
 Using NTFS Permissions


     NTFS Permissions
     NTFS Folder Permissions
     NTFS File Permissions




                                NTFS Partition
                                     C:
NTFS Permissions

     Specific Permissions Required to Assign Permissions
     Permissions Assigned to User Accounts and Groups
     Permission Can Be Denied               NTFS Partition
                                                  C:



                User1        Read



                User2    No Permission
                           Assigned
NTFS Folder Permissions



                          Folder
                       Permissions
                            Read
                            Write
                    List Folder Contents
                      Read & Execute
                            Modify
                          Full Control
NTFS File Permissions



                             File        ~~~~~~
                         Permissions     ~~~~~~
                                         ~~~~~~
                            Read         ~~~~~~
                            Write        ~~~~
                        Read & Execute
                            Modify
                         Full Control
 How Windows 2003 Applies NTFS Permissions


     Multiple NTFS Permissions
     NTFS Permissions Inheritance
     Default NTFS Permissions
     Class Discussion: Applying NTFS Permissions
Multiple NTFS Permissions
                     NTFS Permissions Are Cumulative
                     File Permissions Override Folder Permissions
                     Deny Overrides Other Permissions

                                                      NTFS Partition C:


                                      Read / Write        FolderA
    GroupB
       Write
                           User1
                             Read          Read / Write              File1



                                               Read                  File2
GroupA
Deny Write to File2
NTFS Permissions Inheritance


         Read / Write   FolderA             Inherit Permissions


      Access to FolderB           FolderB



         Read / Write   FolderA

                                            Prevent Inheritance
                                  FolderB

         No access to FolderB
                                            FolderC
Default NTFS Permissions


     NTFS Permissions Automatically Assigned
          When a partition is formatted with NTFS
          When a folder or file is created
          When a user account is added to a folder
Class Discussion: Applying NTFS Permissions

                    Users Group           NTFS Partition
                     Write to Folder1           C:
                    Sales Group
                     Read to Folder1
                                           Folder1
   Users Group
                    Users Group
                     Read to Folder1                 Doc1
  User1             Sales Group
                     Write to Folder2

                                                     Folder2
                    Users Group
                     Modify to Folder1
                    Doc2 should only be                       Doc2
                     accessible to Sales
   Sales Group       Group, and only for
                     read access
 Assigning NTFS Permissions


     Guidelines for Assigning NTFS Permissions
     Setting NTFS Permissions
     Controlling Permissions Inheritance
Guidelines for Assigning NTFS Permissions

   Group Resources to Simplify Administration


   Assign Only the Permissions That Users Need


   Create Groups According to Resource Access Needs


   Assign Read & Execute Permissions for Application Folders


   Assign Appropriate Permissions to Users and File Owner for Public Data


   Assign Permissions Rather Than Deny Permissions
Setting NTFS Permissions
Folder1 Properties

 General Web Sharing Sharing Security

   Name                                             Add...
       Everyone
                                        Select Users, Computers, or Groups
                                                 Remove

                                         Look in:      Entire Directory

                                         Name                              In Folder
                                             BATCH
    Full Control                             INTERACTIVE
    Modify                                   SERVICE
    Read & Execute                           Administrator                 nwtraders. com
                                             Guest                         nwtraders. com
    List Folder Contents
                                             IUSR_SERVER1                  nwtraders. com
    Read
    Write
                                         Name:

    Advanced...                                                                     Check Names
                                         You have selected the following objects:
      Allow inheritable permissions from parent to propagate
      to this object.                     Name                                 In Folder
                                        Administrator                        nwtraders.com
                           OK        Cancel        Apply
Controlling Permissions Inheritance
Folder1 Properties

 General Web Sharing Sharing Security

   Name                                            Add...
       Everyone
                                                 Remove
                       Security

                                  You are preventing any inheritable permissions from propagating to this
                                  object. What do you want to do?

    Full Control                  - To copy previously inherited permissions to this object, click Copy.
    Modify                        - To Remove the inherited permissions and keep only the permissions
    Read & Execute                  explicitly specified on this object, click Remove.
    List Folder Contents          - To abort this operation, click Cancel.
    Read
    Write
                                            Copy            Remove           Cancel

    Advanced...
      Allow inheritable permissions from parent to propagate
      to this object.

                           OK         Cancel         Apply
 Copying and Moving Files and Folders


     Copying Files and Folders
     Moving Files and Folders
     Class Discussion: Copying and Moving Files
Copying Files and Folders

         NTFS Partition                 NTFS Partition           NTFS Partition
                 C:                         C:                       D:

                Copy                                     Copy


Permissions =       Permissions =       Permissions =            Permissions =
 Full Control      Destination Folder    Full Control           Destination Folder

                                        NTFS Partition      Non-NTFS Partition
                                             C:
                                                         Copy


                                        Permissions =             Lose NTFS
  Read, Write Permission                 Full Control             Permissions
Moving Files and Folders

         NTFS Partition                NTFS Partition        NTFS Partition
                 C:                        C:                   D:
                Move                                Move


Permissions =          Permissions =   Permissions =        Permissions =
 Full Control           Full Control    Full Control       Destination Folder

                                       NTFS Partition      Non-NTFS Partition
                                            C:
                                                    Move


                                       Permissions =          Lose NTFS
  Write, Modify Permissions             Full Control          Permissions
Class Discussion: Copying and Moving Files

          NTFS Partition                   NTFS Partition
      (C:)                                  (D:)
                                                   FC
          Users                               Data
                      None

                     Mary
                                              Move      FileA

                                   FileA
          Public
      M
                            Copy
                   FileA
                             Move

                                                                Group 1
 Sharing Resources


     Using Shared Folders
     Applying Shared Folder Permissions
     How Shared Folder Permissions Are Applied
     Guidelines for Administering Shared Folders
Using Shared Folders
     Apply Shared Folders Permissions Only to Entire Folder
     Provide Only Network Security
     Provide Security on Non-NTFS Volumes
     Default Shared Folder Permission Is Full Control
     A User Added to a Shared Folder Gets Read Permission
     A Copy of a Shared Folder Is Not Shared
     A Shared Folder Appears As an Icon of a            Hand
      Holding a Folder
                                       Applications      Data
Applying Shared Folder Permissions



                           Shared Folder
                            Permissions             Data
                               Read
                              Change
                            Full Control



      You Can Allow or Deny Shared Folder Permissions
How Shared Folder Permissions Are Applied


     Multiple Shared Folder Permissions Combine
     Deny Overrides Other Permissions




                                              Data
     Group                  Change (Read)
     Change
                    User                             File
                     Read
Guidelines for Administering Shared Folders


   Replace the Default Everyone Group with the Users Group




   Organize Resources According to Security Requirements




   Use Intuitive Share Names That All Client Computers Can Use
 Creating Shared Folders


     Requirements for Sharing Folders
     Sharing a Folder
     Assigning Shared Folder Permissions
     Modifying Shared Folders
     Connecting to Shared Folders
     Administrative Shared Folders
Requirements for Sharing Folders



    Operating system and role of computer            Group

                                                Administrators or
  Windows 2003 Server As Domain Controller
                                                Server Operators

  Windows 2003 Server As Member Server         Administrators or
  Windows 2003 Professional As Client Computer Power Users
Sharing a Folder
           Applications Properties

           General Web Sharing Sharing Security

                    You can share this folder among other users on your
                    network. To enable sharing for this folder, click
                    Share this folder.
                  Do not share this folder
                  Share this folder
Required
              Share name:       Applications

              Comment:          Application files

              User Limit:        Maximum allowed

                                 Allow                Users

              To set permissions for how users access
              this folder over the network, click Permissions. Permissions

              To configure settings for offline access to
                                                                Caching
              this shared folder, click Caching.



                                         OK            Cancel       Apply
Assigning Shared Folder Permissions
Permissions for Applications

 Security

  Name                                    Add...
     Everyone
                                         Remove
                                            Select Users, Computers, or Groups

                                                           Classroom1

                                               Name                              In Folder
                                                 Account Operators               Classroom1
  Permissions:                   Allow    Deny   Print Operators                 Classroom1
                                                 ANONYMOUS LOGON                 Classroom1
   Full Control                                  Authenticated Users             Classroom1
   Change                                        BATCH                           Classroom1
   Read                                          CREATOR GROUP                   Classroom1
                                                 CREATOR OWNER                   Classroom1

                                                   Name:

                                                                                        Check Names
                                              You have selected the following objects:
                  OK           Cancel       Apply
                                               Name                                 In Folder
                                                  Account Operators                 Classroom1
Modifying Shared Folders
       Applications Properties
        General Web Sharing Sharing Security

               You can share this folder among other users on your
               network. To enable sharing for this folder, click
               Share this folder.
              Do not share this folder
              Share this folder
                            Applications
          Share name:
                            Application files
          Comment:

                            Maximum allowed
          User Limit:
                            Allow    25         Users

         To set permissions for how users access          Permissions
         this folder over the network, click Permissions.
         To configure settings for offline access to
                                                          Caching
         this shared folder, click Caching.

                                                          New Share


                                    OK          Cancel         Apply
Connecting to Shared Folders

                                      Open and Save Dialog Boxes
                                       of Most Applications
                    My Network
  Open                Places          Run on the Start Menu
  Explore
  Search for Computers…   Map Network Drive
                                          Windows can help you connect to a shared network folder
  Map NetworkDrive…
      Network Drive…                      and assign a drive letter to the connection so that you can
                                          access the folder using My Computer.
  Disconnect Network Drive…
                                          Specify the drive letter for the connection and the folder
                                          that you want to connect to:
  Create Shortcut
                                          Drive:       E:
  Rename
                                          Path:         instructor1public             Browse...
  Properties                                         Example: servershare
                                                       Reconnect at logon
                                                      Connect using a different user name.
                                                      Connect to a Web folder or FTP site.



                                                         <Back           Finish            Cancel
Administrative Shared Folders



     Share                            Purpose

  C$, D$, E$   The root of each partition is automatically shared

  Admin$       The C:Winnt folder is shared as Admin$
               When the first printer is created, the folder
  Print$
               containing the printer driver files is shared as Print$
 NTFS Permissions and Shared Folders


     Combining NTFS Permissions with Shared Folders
     Securing Resources with NTFS Permissions
     Class Discussion: Shared Folders and NTFS
      Permissions
Combining NTFS Permissions with Shared Folders

     Shared Folder Permissions Provide Less Security Than
      NTFS Permissions
     Different NTFS Permissions Can Be Assigned for Each
      File and Folder in a Shared Folder
     Shared Folder Permissions and NTFS Permissions Are
      Needed to Gain Access to Files on NTFS Volumes
     Using Shared Folder Permissions to Control Access
      Increases Administrative Overhead
     NTFS Permissions and Shared Folder Permissions
      Combine According to Different Rules
Securing Resources with NTFS Permissions

                        Four Steps

          Identify File Resources to Share


          Add These Files to a Folder


          Secure Folder with NTFS Permissions


          Share the Folder
Class Discussion: Shared Folders
   and NTFS Permissions

                                      NTFS Partition C:
    Users
    Group   FC                         Home



       User1   FC   NTFS Permission               User1



       User2   FC   NTFS Permission               User2
Troubleshooting Access Problems


Err or No Access Permission Assigned to User or Group


Err or Permissions May Have Changed


Err or Changed Permissions Do Not Take Effect
Best Practices
    Assign NTFS Permissions Before You Share a Folder

    Use Share Names Accessible by All Client Computers

    Organize Resources to Simplify Permission Assignments

    Assign Permissions to Groups Rather Than to Individual Users

    Remove Everyone Group and Assign Permissions to Users Group

    Document Locations of Shared Folders and Permissions

    Assign the Most Restrictive Permissions
Review

     Using NTFS Permissions
     How Windows 2003 Applies NTFS Permissions
     Assigning NTFS Permissions
     Copying and Moving Files and Folders
     Sharing Resources
     Creating Shared Folders
     NTFS Permissions and Shared Folders
     Troubleshooting Access Problems
     Best Practices

Weitere ähnliche Inhalte

Andere mochten auch (7)

1556 a 02
1556 a 021556 a 02
1556 a 02
 
Windows Server 2008 Security Overview Short
Windows  Server 2008  Security  Overview  ShortWindows  Server 2008  Security  Overview  Short
Windows Server 2008 Security Overview Short
 
IT103Microsoft Windows XP/OS Chap08
IT103Microsoft Windows XP/OS Chap08IT103Microsoft Windows XP/OS Chap08
IT103Microsoft Windows XP/OS Chap08
 
IT Puls Tromsø - Windows Server 2012 Og Windows 8
IT Puls Tromsø - Windows Server 2012 Og Windows 8IT Puls Tromsø - Windows Server 2012 Og Windows 8
IT Puls Tromsø - Windows Server 2012 Og Windows 8
 
Install Windows Server 2008 enterprise
Install Windows Server 2008 enterpriseInstall Windows Server 2008 enterprise
Install Windows Server 2008 enterprise
 
1556 a 05
1556 a 051556 a 05
1556 a 05
 
Bsm mw10
Bsm mw10Bsm mw10
Bsm mw10
 

Ähnlich wie 1556 a 04

Itt operating systems unit 05 lesson 06
Itt operating systems unit 05 lesson 06Itt operating systems unit 05 lesson 06
Itt operating systems unit 05 lesson 06
blusmurfydot1
 
IT109 Microsoft Operating Systems Unit 05 lesson 06
IT109 Microsoft Operating Systems Unit 05 lesson 06IT109 Microsoft Operating Systems Unit 05 lesson 06
IT109 Microsoft Operating Systems Unit 05 lesson 06
blusmurfydot1
 
Chapter05 Managing File Access
Chapter05      Managing  File  AccessChapter05      Managing  File  Access
Chapter05 Managing File Access
Raja Waseem Akhtar
 
Ch11 OS
Ch11 OSCh11 OS
Ch11 OS
C.U
 

Ähnlich wie 1556 a 04 (20)

Itt operating systems unit 05 lesson 06
Itt operating systems unit 05 lesson 06Itt operating systems unit 05 lesson 06
Itt operating systems unit 05 lesson 06
 
IT109 Microsoft Operating Systems Unit 05 lesson 06
IT109 Microsoft Operating Systems Unit 05 lesson 06IT109 Microsoft Operating Systems Unit 05 lesson 06
IT109 Microsoft Operating Systems Unit 05 lesson 06
 
G Mac Chapter05
G Mac Chapter05G Mac Chapter05
G Mac Chapter05
 
Chapter05 Managing File Access
Chapter05      Managing  File  AccessChapter05      Managing  File  Access
Chapter05 Managing File Access
 
70 271 Stu Chap05
70 271 Stu Chap0570 271 Stu Chap05
70 271 Stu Chap05
 
06 File System
06 File System06 File System
06 File System
 
70-272 Chapter09
70-272 Chapter0970-272 Chapter09
70-272 Chapter09
 
intro unix/linux 09
intro unix/linux 09intro unix/linux 09
intro unix/linux 09
 
Ch11 OS
Ch11 OSCh11 OS
Ch11 OS
 
OSCh11
OSCh11OSCh11
OSCh11
 
OS_Ch11
OS_Ch11OS_Ch11
OS_Ch11
 
2dvm kp 2.pptx
2dvm kp 2.pptx2dvm kp 2.pptx
2dvm kp 2.pptx
 
OS Unit IV.ppt
OS Unit IV.pptOS Unit IV.ppt
OS Unit IV.ppt
 
Linux day 2.ppt
Linux day  2.pptLinux day  2.ppt
Linux day 2.ppt
 
Linux: Basics OF Linux
Linux: Basics OF LinuxLinux: Basics OF Linux
Linux: Basics OF Linux
 
NTFS vs FAT
NTFS vs FATNTFS vs FAT
NTFS vs FAT
 
Chpater 8
Chpater 8Chpater 8
Chpater 8
 
File system
File systemFile system
File system
 
Distributed System by Pratik Tambekar
Distributed System by Pratik TambekarDistributed System by Pratik Tambekar
Distributed System by Pratik Tambekar
 
Linux File System.docx
Linux File System.docxLinux File System.docx
Linux File System.docx
 

Mehr von Lê Liêu

Part05 communication security
Part05 communication securityPart05 communication security
Part05 communication security
Lê Liêu
 
Part04 key exchange protocols
Part04 key exchange protocolsPart04 key exchange protocols
Part04 key exchange protocols
Lê Liêu
 
Part04 basic cryptography
Part04 basic cryptographyPart04 basic cryptography
Part04 basic cryptography
Lê Liêu
 
Part02 access control authentication
Part02 access control   authenticationPart02 access control   authentication
Part02 access control authentication
Lê Liêu
 
Part01 general security concepts
Part01 general security conceptsPart01 general security concepts
Part01 general security concepts
Lê Liêu
 
Part06 infrastructure security
Part06 infrastructure securityPart06 infrastructure security
Part06 infrastructure security
Lê Liêu
 

Mehr von Lê Liêu (12)

1556 a 09
1556 a 091556 a 09
1556 a 09
 
1556 a 08
1556 a 081556 a 08
1556 a 08
 
1556 a 06
1556 a 061556 a 06
1556 a 06
 
1556 a 01
1556 a 011556 a 01
1556 a 01
 
1556 a 00
1556 a 001556 a 00
1556 a 00
 
1556 a 10
1556 a 101556 a 10
1556 a 10
 
Part05 communication security
Part05 communication securityPart05 communication security
Part05 communication security
 
Part04 key exchange protocols
Part04 key exchange protocolsPart04 key exchange protocols
Part04 key exchange protocols
 
Part04 basic cryptography
Part04 basic cryptographyPart04 basic cryptography
Part04 basic cryptography
 
Part02 access control authentication
Part02 access control   authenticationPart02 access control   authentication
Part02 access control authentication
 
Part01 general security concepts
Part01 general security conceptsPart01 general security concepts
Part01 general security concepts
 
Part06 infrastructure security
Part06 infrastructure securityPart06 infrastructure security
Part06 infrastructure security
 

Kürzlich hochgeladen

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 

Kürzlich hochgeladen (20)

GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 

1556 a 04

  • 2. Overview  Using NTFS Permissions  How Windows 2003 Applies NTFS Permissions  Assigning NTFS Permissions  Copying and Moving Files and Folders  Sharing Resources  Creating Shared Folders  NTFS Permissions and Shared Folders  Troubleshooting Access Problems  Best Practices
  • 3.  Using NTFS Permissions  NTFS Permissions  NTFS Folder Permissions  NTFS File Permissions NTFS Partition C:
  • 4. NTFS Permissions  Specific Permissions Required to Assign Permissions  Permissions Assigned to User Accounts and Groups  Permission Can Be Denied NTFS Partition C: User1 Read User2 No Permission Assigned
  • 5. NTFS Folder Permissions Folder Permissions Read Write List Folder Contents Read & Execute Modify Full Control
  • 6. NTFS File Permissions File ~~~~~~ Permissions ~~~~~~ ~~~~~~ Read ~~~~~~ Write ~~~~ Read & Execute Modify Full Control
  • 7.  How Windows 2003 Applies NTFS Permissions  Multiple NTFS Permissions  NTFS Permissions Inheritance  Default NTFS Permissions  Class Discussion: Applying NTFS Permissions
  • 8. Multiple NTFS Permissions  NTFS Permissions Are Cumulative  File Permissions Override Folder Permissions  Deny Overrides Other Permissions NTFS Partition C: Read / Write FolderA GroupB Write User1 Read Read / Write File1 Read File2 GroupA Deny Write to File2
  • 9. NTFS Permissions Inheritance Read / Write FolderA Inherit Permissions Access to FolderB FolderB Read / Write FolderA Prevent Inheritance FolderB No access to FolderB FolderC
  • 10. Default NTFS Permissions  NTFS Permissions Automatically Assigned  When a partition is formatted with NTFS  When a folder or file is created  When a user account is added to a folder
  • 11. Class Discussion: Applying NTFS Permissions  Users Group NTFS Partition Write to Folder1 C:  Sales Group Read to Folder1 Folder1 Users Group  Users Group Read to Folder1 Doc1 User1  Sales Group Write to Folder2 Folder2  Users Group Modify to Folder1  Doc2 should only be Doc2 accessible to Sales Sales Group Group, and only for read access
  • 12.  Assigning NTFS Permissions  Guidelines for Assigning NTFS Permissions  Setting NTFS Permissions  Controlling Permissions Inheritance
  • 13. Guidelines for Assigning NTFS Permissions Group Resources to Simplify Administration Assign Only the Permissions That Users Need Create Groups According to Resource Access Needs Assign Read & Execute Permissions for Application Folders Assign Appropriate Permissions to Users and File Owner for Public Data Assign Permissions Rather Than Deny Permissions
  • 14. Setting NTFS Permissions Folder1 Properties General Web Sharing Sharing Security Name Add... Everyone Select Users, Computers, or Groups Remove Look in: Entire Directory Name In Folder BATCH Full Control INTERACTIVE Modify SERVICE Read & Execute Administrator nwtraders. com Guest nwtraders. com List Folder Contents IUSR_SERVER1 nwtraders. com Read Write Name: Advanced... Check Names You have selected the following objects: Allow inheritable permissions from parent to propagate to this object. Name In Folder Administrator nwtraders.com OK Cancel Apply
  • 15. Controlling Permissions Inheritance Folder1 Properties General Web Sharing Sharing Security Name Add... Everyone Remove Security You are preventing any inheritable permissions from propagating to this object. What do you want to do? Full Control - To copy previously inherited permissions to this object, click Copy. Modify - To Remove the inherited permissions and keep only the permissions Read & Execute explicitly specified on this object, click Remove. List Folder Contents - To abort this operation, click Cancel. Read Write Copy Remove Cancel Advanced... Allow inheritable permissions from parent to propagate to this object. OK Cancel Apply
  • 16.  Copying and Moving Files and Folders  Copying Files and Folders  Moving Files and Folders  Class Discussion: Copying and Moving Files
  • 17. Copying Files and Folders NTFS Partition NTFS Partition NTFS Partition C: C: D: Copy Copy Permissions = Permissions = Permissions = Permissions = Full Control Destination Folder Full Control Destination Folder NTFS Partition Non-NTFS Partition C: Copy Permissions = Lose NTFS Read, Write Permission Full Control Permissions
  • 18. Moving Files and Folders NTFS Partition NTFS Partition NTFS Partition C: C: D: Move Move Permissions = Permissions = Permissions = Permissions = Full Control Full Control Full Control Destination Folder NTFS Partition Non-NTFS Partition C: Move Permissions = Lose NTFS Write, Modify Permissions Full Control Permissions
  • 19. Class Discussion: Copying and Moving Files NTFS Partition NTFS Partition (C:) (D:) FC Users Data None Mary Move FileA FileA Public M Copy FileA Move Group 1
  • 20.  Sharing Resources  Using Shared Folders  Applying Shared Folder Permissions  How Shared Folder Permissions Are Applied  Guidelines for Administering Shared Folders
  • 21. Using Shared Folders  Apply Shared Folders Permissions Only to Entire Folder  Provide Only Network Security  Provide Security on Non-NTFS Volumes  Default Shared Folder Permission Is Full Control  A User Added to a Shared Folder Gets Read Permission  A Copy of a Shared Folder Is Not Shared  A Shared Folder Appears As an Icon of a Hand Holding a Folder Applications Data
  • 22. Applying Shared Folder Permissions Shared Folder Permissions Data Read Change Full Control  You Can Allow or Deny Shared Folder Permissions
  • 23. How Shared Folder Permissions Are Applied  Multiple Shared Folder Permissions Combine  Deny Overrides Other Permissions Data Group Change (Read) Change User File Read
  • 24. Guidelines for Administering Shared Folders Replace the Default Everyone Group with the Users Group Organize Resources According to Security Requirements Use Intuitive Share Names That All Client Computers Can Use
  • 25.  Creating Shared Folders  Requirements for Sharing Folders  Sharing a Folder  Assigning Shared Folder Permissions  Modifying Shared Folders  Connecting to Shared Folders  Administrative Shared Folders
  • 26. Requirements for Sharing Folders Operating system and role of computer Group Administrators or Windows 2003 Server As Domain Controller Server Operators Windows 2003 Server As Member Server Administrators or Windows 2003 Professional As Client Computer Power Users
  • 27. Sharing a Folder Applications Properties General Web Sharing Sharing Security You can share this folder among other users on your network. To enable sharing for this folder, click Share this folder. Do not share this folder Share this folder Required Share name: Applications Comment: Application files User Limit: Maximum allowed Allow Users To set permissions for how users access this folder over the network, click Permissions. Permissions To configure settings for offline access to Caching this shared folder, click Caching. OK Cancel Apply
  • 28. Assigning Shared Folder Permissions Permissions for Applications Security Name Add... Everyone Remove Select Users, Computers, or Groups Classroom1 Name In Folder Account Operators Classroom1 Permissions: Allow Deny Print Operators Classroom1 ANONYMOUS LOGON Classroom1 Full Control Authenticated Users Classroom1 Change BATCH Classroom1 Read CREATOR GROUP Classroom1 CREATOR OWNER Classroom1 Name: Check Names You have selected the following objects: OK Cancel Apply Name In Folder Account Operators Classroom1
  • 29. Modifying Shared Folders Applications Properties General Web Sharing Sharing Security You can share this folder among other users on your network. To enable sharing for this folder, click Share this folder. Do not share this folder Share this folder Applications Share name: Application files Comment: Maximum allowed User Limit: Allow 25 Users To set permissions for how users access Permissions this folder over the network, click Permissions. To configure settings for offline access to Caching this shared folder, click Caching. New Share OK Cancel Apply
  • 30. Connecting to Shared Folders  Open and Save Dialog Boxes of Most Applications My Network Open Places  Run on the Start Menu Explore Search for Computers… Map Network Drive Windows can help you connect to a shared network folder Map NetworkDrive… Network Drive… and assign a drive letter to the connection so that you can access the folder using My Computer. Disconnect Network Drive… Specify the drive letter for the connection and the folder that you want to connect to: Create Shortcut Drive: E: Rename Path: instructor1public Browse... Properties Example: servershare Reconnect at logon Connect using a different user name. Connect to a Web folder or FTP site. <Back Finish Cancel
  • 31. Administrative Shared Folders Share Purpose C$, D$, E$ The root of each partition is automatically shared Admin$ The C:Winnt folder is shared as Admin$ When the first printer is created, the folder Print$ containing the printer driver files is shared as Print$
  • 32.  NTFS Permissions and Shared Folders  Combining NTFS Permissions with Shared Folders  Securing Resources with NTFS Permissions  Class Discussion: Shared Folders and NTFS Permissions
  • 33. Combining NTFS Permissions with Shared Folders  Shared Folder Permissions Provide Less Security Than NTFS Permissions  Different NTFS Permissions Can Be Assigned for Each File and Folder in a Shared Folder  Shared Folder Permissions and NTFS Permissions Are Needed to Gain Access to Files on NTFS Volumes  Using Shared Folder Permissions to Control Access Increases Administrative Overhead  NTFS Permissions and Shared Folder Permissions Combine According to Different Rules
  • 34. Securing Resources with NTFS Permissions Four Steps Identify File Resources to Share Add These Files to a Folder Secure Folder with NTFS Permissions Share the Folder
  • 35. Class Discussion: Shared Folders and NTFS Permissions NTFS Partition C: Users Group FC Home User1 FC NTFS Permission User1 User2 FC NTFS Permission User2
  • 36. Troubleshooting Access Problems Err or No Access Permission Assigned to User or Group Err or Permissions May Have Changed Err or Changed Permissions Do Not Take Effect
  • 37. Best Practices Assign NTFS Permissions Before You Share a Folder Use Share Names Accessible by All Client Computers Organize Resources to Simplify Permission Assignments Assign Permissions to Groups Rather Than to Individual Users Remove Everyone Group and Assign Permissions to Users Group Document Locations of Shared Folders and Permissions Assign the Most Restrictive Permissions
  • 38. Review  Using NTFS Permissions  How Windows 2003 Applies NTFS Permissions  Assigning NTFS Permissions  Copying and Moving Files and Folders  Sharing Resources  Creating Shared Folders  NTFS Permissions and Shared Folders  Troubleshooting Access Problems  Best Practices