1 File systems security: Shared folders & NTFS permissions, EFS (Week 6, Monday 2/12/2007) © Abdou Illia, Spring 2007.

Slides:



Advertisements
Similar presentations
When you combine NTFS permissions and share permissions the most restrictive effective permission applies. For example, if you share a folder and assign.
Advertisements

1 Chapter Overview Understanding and Applying NTFS Permissions Assigning NTFS Permissions and Special Permissions Solving Permissions Problems.
1 Chapter Overview Understanding NTFS Permissions Assigning NTFS Permissions Assigning Special Permissions.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 5: Managing File Access.
1 Distributed File System, and Disk Quotas (Week 7, Thursday 2/21/2007) © Abdou Illia, Spring 2007.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 5: Managing File Access.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 7: Advanced File System Management.
MIS Chapter 51 Chapter 5 – Managing File Access MIS 431 Created Spring 2006.
1 Review For Exam 2 (Week 8, Monday 3/1/2004) © Abdou Illia, Spring 2004.
Hands-On Microsoft Windows Server 2003 Administration Chapter 5 Administering File Resources.
MIS 431 Chapter 71 Ch. 7: Advanced File Management System MIS 431 Created Spring 2006.
70-270, MCSE/MCSA Guide to Installing and Managing Microsoft Windows XP Professional and Windows Server 2003 Chapter Nine Managing File System Access.
Lesson 4: Configuring File and Share Access
By Rashid Khan Lesson 8-Crowd Control: Controlling Access to Resources Using Groups.
5.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 5: Working with File Systems.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 7: Advanced File System Management.
1 Review For Exam 2 (Week 8, Wednesday 3/1/2006) © Abdou Illia, Spring 2006.
1 Securing Network Resources Understanding NTFS Permissions Assigning NTFS Permissions Assigning Special Permissions Copying and Moving Files and Folders.
File systems security: Shared folders & NTFS permissions, EFS Disk Quotas (March 30, 2015) © Abdou Illia, Spring 2015.
Group Accounts; Securing Resources with Permissions
1 Using Compressed Files and Folders Applications and operating systems read and write to compressed files. NTFS uncompresses the file before making it.
Microsoft ® Official Course Module 7 Configuring File Access and Printers on Windows ® 8 Clients.
1 Chapter Overview Managing Data Storage Creating Dynamic Disks Implementing Storage Quotas Managing Compression and Encryption.
Tasks Necessary for Setting Up a Hard Disk Initializing the disk with basic or dynamic storage type Creating partitions on basic disks or volumes on dynamic.
MCSE Guide to Microsoft Windows 7 Chapter 5 Managing File Systems.
11 SHARING FILE SYSTEM RESOURCES Chapter 9. Chapter 9: SHARING FILE SYSTEM RESOURCES2 CHAPTER OVERVIEW Create and manage file system shares and work with.
Chapter 5 File and Printer Services
Access Control Lists and NTFS Permissions INFO333 – Lecture Mariusz Nowostawski Noria Foukia.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 6: Windows File and Print Services.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 7: Advanced File System Management.
Sharing Resources Lesson 6. Objectives Manage NTFS and share permissions Determine effective permissions Configure Windows printing.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 7: Advanced File System Management.
C HAPTER 6 NTFS PERMISSIONS & SECURITY SETTING. INTRODUCTION NTFS provides performance, security, reliability & advanced features that are not found in.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 5: Managing File Access.
IOS110 Introduction to Operating Systems using Windows Session 8 1.
Module 4 Managing Access to Resources in Active Directory ® Domain Services.
Managing Groups, Folders, Files and Security Local Domain local Global Universal Objects Folders Permissions Inheritance Access Control List NTFS Permissions.
Chapter 9: SHARING FILE SYSTEM RESOURCES1 CHAPTER OVERVIEW  Create and manage file system shares and work with share permissions.  Use NTFS file system.
MCSE GUIDE TO MICROSOFT WINDOWS 7 Chapter 5 Managing File Systems.
1 Administering Shared Folders Understanding Shared Folders Planning Shared Folders Sharing Folders Combining Shared Folder Permissions and NTFS Permissions.
Module 3 Configuring File Access and Printers on Windows ® 7 Clients.
Module 3 Configuring File Access and Printers on Windows 7 Clients.
Module 3: Configuring File Access and Printers on Windows 7 Clients
Chapter 8 Configuring and Managing Shared Folder Security.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 11: Managing Access to File System Resources.
MCSE Guide to Microsoft Windows Vista Professional Chapter 5 Managing File Systems.
Page 1 NTFS and Share Permissions Lecture 6 Hassan Shuja 10/26/2004.
Lecture 6 File, Folder and Share Security. Objectives Managing file and folder security.
1 Introduction to NTFS Permissions Assign NTFS permissions to specify Which users and groups can gain access to folders and files What they can do with.
Module 4: Managing Access to Resources. Overview Overview of Managing Access to Resources Managing Access to Shared Folders Managing Access to Files and.
MCSE GUIDE TO MICROSOFT WINDOWS 7 Chapter 5 Managing File Systems.
Managing Data by Using NTFS. Overview Introduction to NTFS Permissions How Windows 2000 Applies NTFS Permissions Using NTFS Permissions Using Special.
Module 4: Managing Access to Resources. Overview Overview of Managing Access to Resources Managing Access to Shared Folders Managing Access to Files and.
Configuring and Managing Resource Access Lecture 5.
1 Chapter Overview Understanding Shared Folders Planning, Sharing, and Connecting to Shared Folders Combining Shared Folder Permissions and NTFS Permissions.
1 Introduction to Shared Folders Shared folders provide network users access to files. Users connect to the shared folder over the network. Users must.
Sharing Resources Lesson 6. Objectives Manage NTFS and share permissions Determine effective permissions Configure Windows printing.
11/06/ أساسيات الأتصال و الشبكات Communication & Networks Fundamentals lab 5.
Windows Vista Configuration MCTS : NTFS Security Features and File Sharing.
11 SUPPORTING WINDOWS XP FILE AND FOLDER ACCESS Chapter 5.
ITMT Windows 7 Configuration Chapter 6 – Sharing Resource ITMT 1371 – Windows 7 Configuration 1.
Introduction to NTFS Permissions
Module 4: Managing Access to Resources
Managing Data by Using NTFS
File systems security: Shared folders & NTFS permissions, EFS Disk Quotas (October 26, 2016) © Abdou Illia, Fall 2016.
Managing Data by Using NTFS
Chapter 9: Managing Groups, Folders, Files, and Object Security
Creating and Managing Folders
Presentation transcript:

1 File systems security: Shared folders & NTFS permissions, EFS (Week 6, Monday 2/12/2007) © Abdou Illia, Spring 2007

2 Learning Objective Understand  Shared Folders Assign  Shared Folder permissions  NTFS Permissions Understand EFS

3 FAT vs. NTFS FAT Supports partitions up to 4 GB (FAT16) and 2 TB (FAT32) Provides only folder-level security Allows limited permission setting (Read, Change, Full Control) NTFS Supports lager partitions size than FAT (w/o disk performance decrease) File-level and Folder-level security Data compression File encryption (Encrypting File System) Disk quotas management Needed for AD services Faster access to data Remote storage: provides an extension to your disk space by making removable media (such as tapes) more accessible. Note: Windows and MS-DOS-based applications can read compressed files because they are automatically decompressed by NTFS when requested. Decision about what file system to use depends on:  Whether multiple OS will be installed on the computer  Security requirements for the system

4 Shared Folder ? A folder used to provide network users with access to file resources. When a folder is shared on a server, users can connect to the server and gain access to the files it contains.

5 Shared Folders To see all shared folders on a computer: 1)Click Start. Then click Run 2)Type \\ComputerName (where ComputerName is a valid network computer name like SRVDC18) 3)Click OK. To share a folder on a computer: 1)Open My Computer (Right-click/Open) 2)Select a disk, then the folder to share 3)Right-click the selected folder 4)Click Properties 5)Click the Sharing tab 6)Check Share this folder 7)Click Apply, and then OK. Requirements for creating a shared folder:  Any supported File system (FAT, NTFS)  If server in a domain, you must be Administrator or Server Operator  If server in a workgroup, you must be Administrator or Power user  If client computer running a workstation OS, you must be Administrator or Power user Note: Users that are granted the Create Permanent Shared Objects right can also create shared folders on the computer where the right is assigned OR 1)Open Computer Management 2)In the console tree, double-click Shared Folders 3)Click Shares

6 Shared folder permissions A shared folder can contain application programs, data or other users’ personnel data Each type of data can require different permissions Subfolder Subfolder Subfolder Subfolder 4 File 1File 2File 3 Shared Folder User 1 User 3 User 2 With FAT, permissions could only be set for folders, not for individual files If permissions at file level are required, you need to use NTFS permissions

7 Shared Folder Permissions Shared folder permissions do not restrict access to users who gain access to the folder at the computer where the folder is stored. Shared folder permissions are the only way to secure network resources on FAT partitions. The default folder permission is Full Control. You can allow or deny shared folder permissions to individual users or to user groups. Read - Display folder names, filenames, file data and attributes - Run program files ChangeRead permission + - Create folders, add files to folders, change data in files, append data to files, change files attributes, delete folders and files. Full ControlChange permission + - Change file permissions and take ownership of files

8 Assigning Shared Folders permissions 1)Open My Computer (Right-click/Open) 2)Select the disk, then the folder 3)Right-click the selected folder 4)Click Properties 5)Click the Sharing tab 6)Click Permissions 7)Assign permissions 8)Click OK, and then OK.

9 Shared Folder Permissions’ Rules Multiple Permissions (The Combination Rule)  If a user is assigned a permission for a Shared folder and  If the use user belongs to a group to which a different permission is assigned,  Then the user’s effective permissions are the combination of the user and group permissions Deny overrides Allow  If you deny a shared folder permission to a user and  If you allow the same permission to a group the user belongs to  Then the user will not have that permission. Copying or Moving Shared folders  If you copy a Shared folder, the original folder is shared but not the copy  If you move a Shared folder, it is no longer shared.

10 Guidelines for Shared Folder Permissions Determine which groups need access to each resource and the level of access they require. Assign permissions to groups instead of user accounts to simplify access administration. Assign the most restrictive permissions that still allow users to perform required tasks. Use intuitive share names so that users can easily recognize and locate resources.

11 Administrative & Hidden shares Administrative shares (created by default):  All hard drives are shared as C$, D$, etc.  The system folder (\WINNT) is shared as Admin$  Driver’s folder for printers (\Winnt\System32\Spool\Drivers) is shared as Print$ Hidden shares (created by users)  Share name should end with $ for the share to be hidden  Not visible by other users unless they know the name  If a user knows the name of a hidden share, he/she can access the share using the UNC name  Start/Run. Then type \\ComputerName\ShareName Universal Naming Convention (UNC) name

12 NTFS permissions If permissions at file level are required, and/or If more specific permissions are required  Then, NTFS permissions must be used 1)Open My Computer (Right-click/Open) 2)Select the disk, then the folder/file to share 3)Right-click the selected folder or file 4)Click Properties 5)Click the Security tab 6)Assign permissions 7)Click Apply, and then OK. Assigning NTFS permissions

13 Standard NTFS permissions ReadUser can open and view content of files/folders. They can also view objects ownership, assigned permissions, and objects attributes (Read-Only, Hidden, etc.) Write Read permission + - Create new files/subfolders in a folder - Change attributes List Folder ContentsCan only view names of folders/files Read and Execute Read and List Folder Content permissions + - Ability for users to navigate through folders for which they don’t have permission in order to get files and subfolders for which they do have permissions. Modify Read + Write + Read and Execute permissions (Users can view, create, delete, modify content of folders, etc.) Full ControlUsers can do everything

14 Extended NTFS permissions Execute File List Folder / Read File Read Attributes Read Extended Attributes Create Files / Write Data Write Attributes Write Extended Attributes Delete Subfolders and Files Read Permissions Change Permissions Take Ownership

15 NTFS permissions Folder SubFolder1 File1.txt File2.txt SubFolder2 File1.doc File2.exe SubFolder3 Access Control List User1Execute File, etc. User 2Read File, etc. …..…… With NTFS permissions, you have an ACL for each resource (Folder, file, etc.) you can assign permissions for.

16 NTFS Permissions’ Rules Multiple Permissions  NTFS file permissions take priority over NTFS folder permissions A user can always access files for which he/she has permissions using UNC. E.g. \\SRVDC16\Data\file1.txt  Denying a permission for a user blocks that permission, even if the permission is granted to a group the user belongs to. Permission Inheritance  By default, permissions assigned for the parent folder are inherited at subfolder and file level  To prevent automatic inheritance, explicit permissions assignments must be done at subfolder and/or file levels. Copying or Moving Files and Folders  When a file/folder is moved within an NTFS partition, it retains its permissions  When a file/folder is copied to another NTFS partition, it inherits the permissions of the destination folder (Golden rule)  When a file/folder is copied to a FAT partition, it loses its NTFS permissions

17 Shares & permissions: Recap Sharing folders/files Setting permissions FATNTFSFATNTFS Folders/Subfolders YES YES (but limited) YES Files NO YES

18 Encrypting File System EFS is NOT used to encrypt data when being transmitted. EFS is used to encrypt data stored on storage media

19 Why use EFS? With NTFS permission, if someone is given the take ownership permission on your file/folder, they can change permissions and access your file/folder With EFS, in addition to access rights, a de-encryption key is needed to read a file*. If someone got a copy of your file, they cannot read its content. Note 1: * When you logon, a private de-encryption key is automatically issued to you by W2003 Note 2: Only the file/folder’s creator or the Recovery Agent (the Administrator) can decrypt the file/folder

20 How to encrypt a folder 1. Right-click the folder you want to encrypt 2. Click Properties 3. In General tab, click the Advanced button Note 1: The command line cipher could also be used to encrypt Note 2: Golden rule doesn’t apply to encrypted files/folders

21 Exercise Logon using a regular user account Create a folder called Lab3-XX (where XX is your computer number) directly under the root of the C: drive. Encrypt the Lab3-XX folder Answer the following questions  If you copy the encrypted folder to another NTFS partition, it will loose it encryption properties.TF  Another user logon to your network. That user can read your encrypted file only if he/she took ownership of your encrypted file, and changed the permissions.TF