Sharing Resources Lesson 6. Objectives Manage NTFS and share permissions Determine effective permissions Configure Windows printing.

Slides:



Advertisements
Similar presentations
1 Chapter Overview Understanding Printer Administration Managing Printers Managing Documents Administering Printers Using a Web Browser Troubleshooting.
Advertisements

1 Chapter Overview Understanding and Applying NTFS Permissions Assigning NTFS Permissions and Special Permissions Solving Permissions Problems.
1 Chapter Overview Understanding NTFS Permissions Assigning NTFS Permissions Assigning Special Permissions.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
1 File systems security: Shared folders & NTFS permissions, EFS (Week 6, Monday 2/12/2007) © Abdou Illia, Spring 2007.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 5: Managing File Access.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 5: Managing File Access.
9.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 9: Installing and Configuring.
Hands-On Microsoft Windows Server 2003 Administration Chapter 5 Administering File Resources.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 8: Implementing and Managing Printers.
70-270, MCSE/MCSA Guide to Installing and Managing Microsoft Windows XP Professional and Windows Server 2003 Chapter Nine Managing File System Access.
11 SHARING FILE SYSTEM RESOURCES Chapter 9. Chapter 9: SHARING FILE SYSTEM RESOURCES2 CHAPTER OVERVIEW  Create and manage file system shares and work.
Lesson 4: Configuring File and Share Access
By Rashid Khan Lesson 8-Crowd Control: Controlling Access to Resources Using Groups.
5.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 5: Working with File Systems.
Hands-On Microsoft Windows Server 2003 Administration Chapter 6 Managing Printers, Publishing, Auditing, and Desk Resources.
1 Securing Network Resources Understanding NTFS Permissions Assigning NTFS Permissions Assigning Special Permissions Copying and Moving Files and Folders.
Group Accounts; Securing Resources with Permissions
Configuring Print Services Lesson 7. Skills Matrix Technology SkillObjective DomainObjective # Deploying a Print ServerConfigure and monitor print services.
Microsoft ® Official Course Module 7 Configuring File Access and Printers on Windows ® 8 Clients.
Printing Terminology. Requirements for Network Printing At least one computer to operate as the print server Sufficient RAM to process documents Sufficient.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
11 SHARING FILE SYSTEM RESOURCES Chapter 9. Chapter 9: SHARING FILE SYSTEM RESOURCES2 CHAPTER OVERVIEW Create and manage file system shares and work with.
Chapter 5 File and Printer Services
Access Control Lists and NTFS Permissions INFO333 – Lecture Mariusz Nowostawski Noria Foukia.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 6: Windows File and Print Services.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory Chapter 9: Active Directory Authentication and Security.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
Week 9 Objectives Securing Files and Folders Protecting Shared Files and Folders by Using Shadow Copies Configuring Network Printing.
Implementing File and Print Services
1 Managing Printers (Week 12, Monday 3/26/2007) © Abdou Illia, Spring 2007.
C HAPTER 6 NTFS PERMISSIONS & SECURITY SETTING. INTRODUCTION NTFS provides performance, security, reliability & advanced features that are not found in.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 5: Managing File Access.
IOS110 Introduction to Operating Systems using Windows Session 8 1.
Module 4 Managing Access to Resources in Active Directory ® Domain Services.
Managing Groups, Folders, Files and Security Local Domain local Global Universal Objects Folders Permissions Inheritance Access Control List NTFS Permissions.
Chapter 9: SHARING FILE SYSTEM RESOURCES1 CHAPTER OVERVIEW  Create and manage file system shares and work with share permissions.  Use NTFS file system.
1 Chapter Overview Creating Drive and Folder Shares Using Distributed File System Installing Network Printers Administering Network Printers Managing Share.
1 Administering Shared Folders Understanding Shared Folders Planning Shared Folders Sharing Folders Combining Shared Folder Permissions and NTFS Permissions.
Module 3 Configuring File Access and Printers on Windows ® 7 Clients.
Module 3 Configuring File Access and Printers on Windows 7 Clients.
Module 3: Configuring File Access and Printers on Windows 7 Clients
Chapter 8 Configuring and Managing Shared Folder Security.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 11: Managing Access to File System Resources.
Page 1 NTFS and Share Permissions Lecture 6 Hassan Shuja 10/26/2004.
Lesson 13: Configuring Shared Resources
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
CN1260 Client Operating System Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
1 Introduction to NTFS Permissions Assign NTFS permissions to specify Which users and groups can gain access to folders and files What they can do with.
Module 4: Managing Access to Resources. Overview Overview of Managing Access to Resources Managing Access to Shared Folders Managing Access to Files and.
Module 4: Managing Access to Resources. Overview Overview of Managing Access to Resources Managing Access to Shared Folders Managing Access to Files and.
Configuring and Managing Resource Access Lecture 5.
1 Chapter Overview Understanding Shared Folders Planning, Sharing, and Connecting to Shared Folders Combining Shared Folder Permissions and NTFS Permissions.
Windows Server 2003 檔案分享管理 林寶森
1 Introduction to Shared Folders Shared folders provide network users access to files. Users connect to the shared folder over the network. Users must.
Sharing Resources Lesson 6. Objectives Manage NTFS and share permissions Determine effective permissions Configure Windows printing.
11/06/ أساسيات الأتصال و الشبكات Communication & Networks Fundamentals lab 5.
Configuring Print Services Lesson 7. Print Sharing Print device sharing is another one of the most basic applications for which local area networks were.
11 SUPPORTING WINDOWS XP FILE AND FOLDER ACCESS Chapter 5.
Lesson 14: Configuring File and Folder Access MOAC : Configuring Windows 8.1.
ITMT Windows 7 Configuration Chapter 6 – Sharing Resource ITMT 1371 – Windows 7 Configuration 1.
Introducing, Installing, and Upgrading Windows 7
File and Print Services
Introduction to NTFS Permissions
Lesson 4: Configuring File and Share Access
Module 4: Managing Access to Resources
Introducing NTFS Reliability Security Long file names Efficiency
Creating and Managing Folders
Network Locations in Windows 7
Presentation transcript:

Sharing Resources Lesson 6

Objectives Manage NTFS and share permissions Determine effective permissions Configure Windows printing

Permissions Privileges granted to specific system entities, such as –Users –Groups –Computers Enabling the entities to perform a task or access a resource Example - you can grant as pecific user permission to read a file, while denying that same user the permissions needed to modify or delete the file

Managing Permissions NTFS permissions - Control access to the files and folders stored on disk volumes formatted with the NTFS file system Share permissions - Control access to files and folders shared over a network Registry permissions - Control access to specific parts of the Windows registry Active Directory permissions - Control access to specific parts of an Active Directory hierarchy

Windows Permission Architecture Access Control List (ACL) Access Control Entries (ACEs) Security principal Folder ACL Sales – Read Managers – Full Control JSmith – Deny Access ACEs Security Principal Permission ACL Sales – Read Managers – Full Control JSmith – Deny Access

Windows Permission Architecture It is crucial to understand that, in all of the Windows operating systems, permissions are stored as part of the element being protected, not the security principal (user or Group) being granted access. when you grant a user the NTFS permissions needed to access a file, the ACE you creare is stored in the file's ACL; it is not part of the user account. You can move the file to a different location, and its permissions go with it.

The Security Tab element being protected security principals permissions

Standard and Special Permissions Permissions allow you to grant specific degrees of access to security principals (granular). Preconfigured permission combinations are called Standard Permissions. Special Permissions are more granular and can be applied individually, but are rarely used.

Advanced Security Settings Dialog Box

Allowing and Denying Permissions Additive –Start with no permissions and then grant Allow permissions (preferred method) Subtractive –Start by granting Allow permissions and then grant Deny permissions

Inheriting Permissions The most important principle in permission management is that permissions tend to run downward through a hierarchy. This is called permission inheritance

Inheriting Permissions Now the administrator assigns each user the Allow Full Control permission By doing this the administrator does not compromising the security of the other users‘ folders

Preventing Permission Inheritance There are two ways to prevent subordinate elements from inheriting permissions from their parents. –Turn off inheritance: V{hen you assign special permissions, you can configure an ACE not to pass its permissions down to its subordinate elements. This effectively blocks the inheritance process –Deny permissions: -When you assign a Deny permission to a system element, it overrides any Allow permissions that the element might have inherited from its parent objects.

Copying and Moving NTFS FIles Copy file to a folder within NTFS volume, inherits folder permissions Copy file to a folder between NTFS volumes, inherits folder permissions Move file to a folder between NTFS volumes, inherits folder permissions Move file to a folder within NTFS volume, retain permissions regardless what permissions the folder may have Copy or move file from FAT32 to NTFS volume, inherits folder permissions

Effective Permissions The combination of Allow permissions and Deny permissions for each security principal: –Allow permissions are cumulative. –Deny permissions override Allow permissions. –Explicit permissions take precedence over inherited permissions.

Allow Permissions When a security principal receives Allow permissions from more than one source, the permissions are combined to form effective permissions. One of the primary principle use in permissions is that they are assigned to groups not users. Deny permission overrides allow permissions

Folder (element) Security Principals Accountants permissions Read - allow Write - allow Administrator Modify - allow Fred is a member of both the Accountants and Administrators group What are Fred’s effective permissions?

Folder (element) Security Principals Accountants permissions Read -allow Write – allow Modify - allow Administrator Read -allow Write – allow Modify - deny Fred is a member of both the Accountants and Administrators What are Fred’s effective permissions?

Effective Permissions Tab

Managing NTFS Permissions Security Descriptor Folder – Secured Object ACL Sales – Read Managers – Full Control JSmith – Deny Access Access Token Jsmith Groups: Sales SID When you log on using your user ID and password you receive the Access Token The Access Token is compared with the ACE’s in the ACL to determine what you can do with the resource What can Jsmith do with this folder?

Assigning Standard NTFS Permissions

NTFS Standard Permissions – Full Control Folder Modify the folder permissions. Take ownership of the folder. Delete subfolders and files contained in the folder. Perform all actions associated with all of the other NTFS folder permissions. File Modify the file permissions. Take ownership of the file. Perform all actions associated with all of the other NTFS file permissions.

NTFS Standard Permissions – Modify Folder Delete the folder. Perform all actions associated with the Write and the Read & Execute permissions. File Modify the file. Delete the file. Perform all actions associated with the Write and the Read & Execute permissions.

NTFS Standard Permissions – Read & Execute Folder Navigate through restricted folders to reach other files and folders. Perform all actions associated with the Read and List Folder Contents permissions. File Perform all actions associated with the Read permission. Run applications.

NTFS Standard Permissions – List Folder Folder View the names of the files and subfolders contained in the folder. File Not applicable

NTFS Standard Permissions – Read Folder See the files and subfolders contained in the folder. View the ownership, permissions, and attributes of the folder. File Read the contents of the file. View the ownership, permissions, and attributes of the file.

NTFS Standard Permissions – Write Folder Create new files and subfolders inside the folder. Modify the folder attributes. View the ownership and permissions of the folder. File Overwrite the file. Modify the file attributes. View the ownership and permissions of the file.

Assigning Special NTFS Permissions

Resource Ownership Every file and folder on an NTFS drive has an owner. The owner always has the ability to modify the permissions, even if current permissions settings deny them access. The owner is the person who created the file or folder. Others with the “Take Ownership” permission can become the owner.

SHARING FILES AND FOLDERS

Folder Sharing in Windows 7 Any folder sharing Public folder sharing Homegroup sharing

Sharing with Homegroups Uses the Home network location to share the contents of libraries among all users Automatically configured Shares libraries in the users profiles Can add libraries

Creating a Homegroup

Working with Homegroups

Sharing the Public Folder Simplest way to give clients file sharing capability (small business networking) Network Discovery and Public Folder Sharing must be turned on Copy files to be shared to the Public folder

Any Folder Sharing Full control over what material on the computer is shared Which users have access and to what degree they have access

Managing Share Permissions Share permissions are independent from other permissions. With Password Protected Sharing enabled, users must have user accounts on the computer or in a domain.

Combining Share and NTFS Permissions NTFS Volume Shared Folder File A File B Share Permissions NTFS Permissions FC R Users On networks already possessing a well-planned system of NTFS permissions, share permissions are not really necessary. In this case, you can safely grant the Full Control share permission to Everyone, and allow the NTFS permissions to provide securiry.

WORKING WITH PRINTERS

Windows Print Architecture Printer - the software interface through which a computer communicates with a print device Printer Driver - a device driver that converts the print jobs generated by applications into an appropriate string of commands for a specific print device Printer Server - a computer (or stand-alone device) that receives print jobs from clients and sends them to print devices that are either locally attached or connected to the network Print Device - the actual hardware that produces hard copy documents on paper or other print media

Windows Printing Flexibility Stand-alone local printing Printer shared on the network Print device connected directly to LAN Create a printer pool (one print server with more than one print device) Connect multiple printer servers to a single print device

Adding a Local Printer Most common configuration for home, small business, or workgroups Local users can print their own jobs Can share the printer with other network users

Add a Local Printer 1

Add a Local Printer 2

Sharing a Printer

Configuring Printer Security When password protected sharing is turned on, users must log on to the computer with a user account that has a password. Users must have the appropriate permissions to access the printer.

Printer Permissions

Managing Documents Pausing, resuming, restarting, and canceling documents in the print queue

Managing Printers Printer priority Scheduling printer access Creating a Printer Pool

Skills Summary Windows 7 has several sets of permissions, which operate independently of each other, including NTFS permissions, share permissions, registry permissions, and Active Directory permissions. NTFS permissions enable you to control access to files and folders by specifying just what tasks individual users can perform on them. Share permissions provide rudimentary access control for all of the files on a network share.

Skills Summary (cont.) The printing architecture in Windows is modular, consisting of the print device, a printer, a print server, and a printer driver. A local printer is one that supports a print device directly attached to the computer or attached to the network. A network printer connects to a shared printer hosted by another computer.