Sunteți pe pagina 1din 3

FILE SERVICES ( SMB & NTFS)

There are 2 types of permission:- Share Level Permission & NTFS


permission.
Share Level Permission Share level Permission works on of Folder only.
As Folder can only be shared, and this permission applies to folder
,hence share level permission
Protocol used in share level permission is SMB (shared message Block)
protocol,
SMB protocol checks if the users has been authenticated or denied
access.

There are 3 basic permission in Share Level Permission


1-Full control
2- Modify-Able to add, delete folder inside the parent folder but cannot
delete the folder itself
3-Read-cannot delete, create , can only read
* REMEMBER-DENY OVERIDES ALLOW

Points to remember:if user A is a member of 2 groups, AA & BB and if you set AA group
permission to access a folder and BB group deny the user A is Denied
Access to that folder.

NTFS PERMISSION (New Technology File System )


NTFS permission applies to Folder and Files
NTFS permission are given inside shared folder to give it an extra layer
of security

INHERITANCE:
When you create Files and Folders inside of folders (Parent Folder)
those new Files and folders inherit the permission from the parent
folder
When you setup NTFS permission there are 2 box
1st - include inheritable permission from object parent -means that it
will inherit all that permission from the parent folder / file, if you do not
want to inherit the permission from the parent uncheck the box
2nd-to apply inheritable permission on folder / files even if the 1st box
is unchecked,
Scenario: smb and NTFS scenario
POINTS TO REMEMBER:
1- Its a best practice to use Both SMB AND NTFS Permission together.
2-The Parent shared folder should always be using SMB permission and
the Folders within the Shared folder should be using NTFS
3-Both the permission do not change each other but the deny
permission always
wins the race.
4-when you move folders that have share level permission you will lose
the share level permission
5-when you move folders and files that have NTFS permission they
may either keep the permission or inherit permission of the folder in
which they have been moved.
SHARE AND STORAGE MANAGEMENT:
Share and storage management is a console of microsoft for sharing a
folder and assigning both NTFS and Share permission to that folder.
NFS SHARING
NETWORK FILE SYSTEM- is a feature for UNIX based clients to
access shared resources on the server.

ACCESS BASED ENUMERATON- it is a feature in Share and Storage


management to hide those folders that the user are not given access
or denied.
it makes that folder invisible to the user.

S-ar putea să vă placă și