How to setup a Windows File Server Share with Security Permissions

Поделиться
HTML-код
  • Опубликовано: 22 июл 2022
  • Learn how to setup a Windows file share on Windows Server. In this example, I show you how to create a folder, share the folder to everyone within an Active Directory Domain, and mange the user permissions to the folders using AD security groups, and the map the new shared folder using a mapped drive group policy.
    View the blog post here: www.dannymoran.com/windows-fi...
    How to setup a Windows File Server Share: • How to setup a Windows...
    How to setup DFS Namespaces: • How to setup DFS Names...
    How to setup DFS Replication: • How to setup DFS Repli...
    How to enable Access Based Enumeration: • How to enable Access B...
    Hi, I’m Danny, a London based IT consultant and sporadic blogger. You can view all my blog posts at: www.dannymoran.com
  • НаукаНаука

Комментарии • 79

  • @wopr137
    @wopr137 9 дней назад +1

    Thank you for making this video on AD shares. Makes a lot of sense now seeing how you modify the permissions. Thank you!!

  • @notsync8469
    @notsync8469 4 месяца назад +2

    Thank you for quick and step by step guide, I'm writing a thesis about a file server, and you helped me a lot.

    • @danny_moran
      @danny_moran  4 месяца назад

      Glad it helped! Thanks for watching!

  • @thomaswupping5888
    @thomaswupping5888 5 месяцев назад +2

    Greetings from germany, enjoy your videos! Straight forward to the point, problem solved in a efficient manner. Bravo!

  • @SemisiKatoa
    @SemisiKatoa 4 месяца назад +1

    Love it! Direct, to the point, simple step- by-step instructions! New Subscriber for sure!

  • @oscarlugo16
    @oscarlugo16 Год назад +2

    This is pure gold! saved my behind today thanks!

    • @danny_moran
      @danny_moran  Год назад

      Glad you found it useful! Thanks for watching, Oscar!

  • @mochagawd
    @mochagawd 2 месяца назад +1

    THIS IS FANTASTIC 🔥

  • @tedybg
    @tedybg Год назад +1

    Very useful! Thanks!

  • @Simulacra001
    @Simulacra001 Год назад +1

    Great video. Thank you

  • @ahpek199
    @ahpek199 6 месяцев назад +1

    awesome sharing. thanks for the effort

  • @christianmllersrensen2489
    @christianmllersrensen2489 3 месяца назад +1

    Thank you a bunch :)

  • @galbiwahdi1180
    @galbiwahdi1180 Месяц назад +1

    Needed this, thank you, keep going with the great help you're offering we keep going with pushing the algorithm, hopefully you make more videos, and one last thing could please when explaining how things are technically done, can you during that process explain why we do it and throw a real life exemple usage, and thank you so much in advance

    • @danny_moran
      @danny_moran  Месяц назад +1

      Thanks for watching and thanks for the feedback!

  • @hassanmohamed4591
    @hassanmohamed4591 11 месяцев назад +1

    thanks alot :)

  • @cristofmanama5125
    @cristofmanama5125 11 месяцев назад

    excelent

  • @azizzainul
    @azizzainul 4 месяца назад +1

    Great

  • @mikelane6126
    @mikelane6126 Год назад +1

    Excellent!

  • @utkarshsinghmar3497
    @utkarshsinghmar3497 8 месяцев назад +1

    Thank you so much for such informational video. I am able to implement exact same thing that you described in this video. The only bizarre thing is that Users are only able to see the drives they have permission to. E.g. HR folder is only visible to sf-hr users, tech is visible to only sf-tech users and same with accounts. How can I get the permissions to be applied in such a way that users can see all the folders but can only access the ones which they have access to. Your reply would be really appreciated. Thanks again!

    • @danny_moran
      @danny_moran  8 месяцев назад +2

      Sounds like you have Access Based Enumeration setup on the file share.
      Have a look at this guide, just do the reverse as this is for setting up ABE: ruclips.net/video/_k6A8-4umPI/видео.html
      Thanks for watching!

  • @abdeenmostafa8264
    @abdeenmostafa8264 11 месяцев назад +1

    Thanks a lot for this helpful one, i wanna ask you about something please, If I want all new created users to have a home folder and mapped automatically whithout modifing the home folder for the new coming user everytime how can i do this?

    • @danny_moran
      @danny_moran  11 месяцев назад +1

      I haven't dealt with Home Folders for a while as we migrated everyone away from them onto OneDrive.
      However, you should be able to setup a PowerShell script that runs on a schedule that automatically identifies any user accounts that don't have a home folder specified in the profile tab of the active directory user object, and then it automatically fills it in and points it to a file share and creates the folder with their username.
      Thanks for watching!

  • @alejandroparrello6493
    @alejandroparrello6493 Год назад +2

    Hi! Good explanation! I have a question to clarify, you set the special permission to a groups unticking delete, chown and tkown to denny users to could do these actions? I have this problem on a fileserver, everytime i check users files properties 😮‍💨🤦... the owner is the user and not the group as you set... sorry about my english, regards from Argentina 😉👋

    • @danny_moran
      @danny_moran  Год назад +3

      The reason I changed the owners of the main folders to a security group is so no one can take ownership of that folder and change the permissions unless they are specifically allowed (by making them a member of that group or they are an domain admin or admin on the file server).
      It is only the main folders that need this ownership change. The files within the folder will likely show the creator of the file as the owner, and this is fine as the access permissions are provided by the folder and not the individual file.
      I hope this clears things up.
      Thanks for watching!

    • @alejandroparrello6493
      @alejandroparrello6493 Год назад +1

      @@danny_moran thx so much Danny! 👏👏😁✌️

  • @TLPenn
    @TLPenn Год назад +2

    Loved the video! It was fast, but priceless. I have two questions, please. Why did you "drop" the mapped drives link Into the domain, (at 8m4s)? I do not know what this accomplished. Can you please clarify? I created the GPO links with in my security groups, for example, Admin-RW-SG or Admin-RO-SG. Also, I noticed you did not change the "Hide/Share this drive" or "Hide/Share all drives" settings (at, 7m50s) within the mapped drive wizard, but the S-drive letter still showed up in the users' explorer. When my users log into their machine, some get, "Could not map all network drives". I turned these settings to, "Show this drive" AND "Show all drives" Just curious why you didn't and why it does not matter, because you sure proved it is not needed. You also made me realize some weak links I left in my setup where I did NOT go and change the advanced rights settings, like unchecking the "Delete", "Change Permissions" and "Take Ownership" ! Thanks so much for your time and effort in sharing this. Again, this is so valuable and you "da" man!

    • @danny_moran
      @danny_moran  Год назад

      When you create a GPO, it gets stored in the 'Group Policy Objects' folder. However, the GPO is not yet applied. You need to 'link' it to either the domain or an organisational unit. You can do this by 'dropping' the GPO over the domain or OU. Or, you can navigate to the OU and create it there and it gets linked automatically.
      As for the 'hide/show this drive' and 'hide/show all drives', I'm not 100% sure on when you would/wouldn't use that option. I've always just left it as 'no change' and never had any issues. If i wanted to hide or remove a drive, I would just use the delete action.
      Thanks for watching!

  • @aolish
    @aolish 6 месяцев назад +1

    Is there a way to modify individual permissions in a group? For example, if you have a group of 5 people under one group (John, Mary, George, Alex, Sam) there doesn't seem to be a way to edit just Alex but rather whatever changes you make applies to all 5 people. Thanks.

    • @danny_moran
      @danny_moran  6 месяцев назад +1

      I would recommend making an additional security group just for Alex, and then giving that new security group whatever permissions Alex requires.
      I avoid giving file permissions directly to user accounts, and always use security groups, even if it's just for one user.
      Thanks for watching!

  • @AliTahreiSh
    @AliTahreiSh Год назад +1

    helpful

  • @user-yd4bb2md9g
    @user-yd4bb2md9g Месяц назад +1

    Tanks for example, It`s great. had issues with permissions on Volumes/Folders Side.
    Now is more clear. (btw i red all comments, was also helpfull :D )
    Question: the permissions must be on the Folders? Can I controll hole permissions in GPOs that is linked to some OU? (I tried and working, just with users, not Groups in Item Targeting Level...) And shared Folder is with permission Group "Everyone" and Full Controll)
    Tank you

    • @danny_moran
      @danny_moran  Месяц назад

      No, you can only use group policy to map the drives.
      You still need to manually set the permissions on the folder.
      Thanks for watching!

  • @edwardmakabling418
    @edwardmakabling418 4 месяца назад +2

    Hello... Juat want to ask.. User wasnt be able to save the after they edit for example in MS excel.

    • @danny_moran
      @danny_moran  4 месяца назад

      Does the user have modify permission on the file they are trying to edit?

  • @anorguli
    @anorguli 9 месяцев назад +1

    thanx for the video. When I trying to change owner on a folder to security group i have an error message "its impossible to assign this object type as owner. " Any user can be assigned without a problem, but not a security group. Do you have idea why?

    • @danny_moran
      @danny_moran  9 месяцев назад

      Is this an empty folder or a folder with files/folders in it?
      Sounds like it could be struggling to change the owner of files/folders within the folder.
      You may have to search the error message online to see how to get around this.
      Thanks for watching!

  • @TheTF01
    @TheTF01 5 месяцев назад +1

    With a Quickbooks share would you leave the "QBDataServiceUser"s that are automatically generated?

    • @danny_moran
      @danny_moran  5 месяцев назад

      I haven't used QuickBooks in years, but, I would assume that if you removed the permission from the account then QuickBooks would stop working.
      Thanks for watching!

  • @adamnowicki2626
    @adamnowicki2626 3 дня назад +1

    Hello! great vid, but I don't have permissions tab in folder's propeties... any idea?

    • @danny_moran
      @danny_moran  3 дня назад

      The security tab is missing? I don't think I've ever seen it not be there.

  • @yordanov5.0
    @yordanov5.0 8 месяцев назад +1

    How can we possibly make that only the shared folders are seen by the specific users rather than all the shared folders(including those with restricted acces) ? I tried with access-based enumeration but sadly nothing changes.

    • @danny_moran
      @danny_moran  8 месяцев назад +1

      The way you hide folders from people who don't have permission to access them is to use Access Based Enumeration, like you mentioned.
      I have a guide on setting this up if you want to double check your config: ruclips.net/video/_k6A8-4umPI/видео.html
      Thanks for watching!

  • @aolish
    @aolish 6 месяцев назад +1

    I have another question which is an auto map question, is there a way to add a user to a security group that is not in the same OU? For some reason I am only able to add a user in the same security group that is in the same OU, but if its a different OU the drive will not auto map. Any help is appreciated.

    • @danny_moran
      @danny_moran  6 месяцев назад

      If the user is not within an organisational unit that the group policy is applied to, then the user will never get the drive map even if they are a member of the security group.
      You will need to link the gpo to whatever the ou the user is a member of.
      Thanks for watching!

  • @duhabagca2778
    @duhabagca2778 10 месяцев назад +1

    hello dude what exactly did you do at 8:09 which keys did you press can you help me

    • @danny_moran
      @danny_moran  10 месяцев назад

      I'm not sure what you mean? I just changed from my windows server virtual machine to my windows 11 virtual machine.
      Thanks for watching!

  • @NishfaanNaseer
    @NishfaanNaseer 23 дня назад +1

    how do you have hostname ip and other information showed up on the wallpaper there? can share the gp or script to do that?

    • @danny_moran
      @danny_moran  22 дня назад

      I have a guide on how to set this up: ruclips.net/video/ZnCEpFzd9VU/видео.html
      Thanks for watching!

  • @pavanpani267
    @pavanpani267 10 месяцев назад +1

    thanks for the video..
    Can u pls explain how to create shared folders with read and write permissions with no delete permissions.
    user should not have delete permissions, but should edit the data.

    • @danny_moran
      @danny_moran  10 месяцев назад +1

      I show this in the video. When assigning the user permissions to the folder, if you untick the 'Delete' box under advanced permissions, then the user won't be able to delete the folder but still read and write to files within the folder.
      Thanks for watching!

  • @JohnFekoloid
    @JohnFekoloid Год назад +1

    Was following, but got lost in the Active Directory part. Guess I have to start off with Active Directory first.

    • @danny_moran
      @danny_moran  Год назад

      Sorry, I'm not sure what you mean by this?

    • @JohnFekoloid
      @JohnFekoloid Год назад +1

      @@danny_moran Didn't mean to alarm you. I've heard of Active directory. But I don't know how to set it up. Your file server setup shows you clicking somethings about Active Directory, like the file server only works, when Active Directory is also working.

    • @danny_moran
      @danny_moran  Год назад +1

      The method in this video only works if you have a local Active Directory domain, and both the file server and client workstations connected to the domain.

  • @eavenhuang7419
    @eavenhuang7419 20 дней назад +1

    I set up the permissions but I'm facing an issue that the logged in user has to be the AD account who has permission to a specific shared folder. When I logged in to Windows as a local PC account, still the same PC, same network same IP address being obtained, even I used the option of different credentials to connect, I typed the AD user's credentials, It always failed to access the shared folders. Any idea?

    • @danny_moran
      @danny_moran  18 дней назад

      Why are you logging into a domain joined workstation using the local account?
      If the user account you're entering the credentials for has permissions to access the folder, then it should work. I don't know why it wouldn't.
      What is the error?

    • @eavenhuang7419
      @eavenhuang7419 14 дней назад +1

      @@danny_moran actually i was trying to simulate the scenario where users used their own laptop with local account only, anyway, i was not giving everyone FULL control in the first place but after following your steps, the configuration seems working fine now. Thanks a million!

    • @danny_moran
      @danny_moran  12 дней назад

      Glad you've managed to get it working!

  • @eavenhuang7419
    @eavenhuang7419 20 дней назад +1

    By the way at your very first step, why do you need to grant FULL CONTROL for everyone then remove the users and disable inheritance? This is where I don't understand and still very confused😅😅

    • @eavenhuang7419
      @eavenhuang7419 20 дней назад +1

      I'm referring to setting up the Shared (parent folder)

    • @danny_moran
      @danny_moran  18 дней назад

      This is so everyone can actually access the shared folder.
      The permissions are then setup on the sub-folders.
      Thanks for watching!

  • @MysticMaven
    @MysticMaven 5 месяцев назад +1

    God I hate Windows administration with a passion