Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations John Tel on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

managing users and shared folders over network

Status
Not open for further replies.

danwand

Programmer
Jun 8, 2003
100
GB
Current network situation. I have 3 computers all on windows XP Pro linked to a single workgroup network (using NIC cards and a hub, NO SERVER). All computers on the same site, but in different offices, i have assigned each computer a network ID and static IP address.
Simple file sharing has been turned off, so i do have access to sharing and security tabs. Description of computer in workgroup follows

COMPUTER 1. NAME: "SALES-HOST". USERS: "Marie". ACCOUNT TYPE: Administrator.

FILES SHARED ON NETWORK:
SAGE ACCOUNTS FILE - This computer is designated as the Host computer for Sage line 50 accounts. A folder in 'C' drive program files is shared on the network - other computers on the network will map a network drive to this folder and carry out a net install of Sage so that they can also use the program. All updated data from users on other computers is stored on this host computer. No unauthorised access to sage is possible because anyone who runs the program must have a valid user name and password to access the data held by sage.

MARIES DOCUMENTS - Most of the data pertaining to the company is held in this folder. Within Maries documents is another 8 folders relating to particular areas of the business.

FILES ON NETWORK THAT NEED TO BE ACCESSED:
None.

COMPUTER 2. NAME: "DESIGN". USERS: "David". ACCOUNT TYPE: Administrator.

FILES SHARED ON NETWORK:
None.

FILES ON NETWORK THAT NEED TO BE ACCESSED:
From "HOST" - "Maries Documents."
"Sage accounts folder."
From "PRODUCTION" - "All shared documents"

COMPUTER 3. NAME: "PRODUCTION". USER: "Nev". ACCOUNT TYPE: Administrator
USER: "Brian". ACCOUNT TYPE: Limited user.

This is 1 computer shared by 2 people, each of which have their own log-in. All documents saved by each user is saved in default "SHARED DOCUMENTS" folder.

FILES SHARED ON NETWORK:
SHARED DOCUMENTS - Any documents saved by either user saved in the common "SHARED DOCUMENTS" folder. Both user should have equal permissions to access this folder and it should be shared on the network. The user "David" who has the computer "DESIGN" should be able to view all documents saved by production operatives in their shared folder. Ideally the "SALES-HOST" computer should not have access to this folder although that is not a must have requirement

FILES ON NETWORK THAT NEED TO BE ACCESSED:
From "SALES-HOST" - "MARIES DOCUMENTS"
This is where i am encountering problems. The user "Nev" should have access to most of the folders in "MARIES DOCUMENTS" whereas the user "BRIAN" should not be able to view any of these files. Ideally i need to deny all network access for user "BRIAN", but cannot seem to do this without denying all access to user "NEV" as well (because they are both users on the SAME PC).

I have tried various means of setting up the network to address these requirements but with no luck. Each time i manage to address a particular requirement other nesseccary requirements are not met, i.e. i can prevent netwrok access for user "Brian" but this means user "Nev" no longer has network access, or user "David" in "DESIGN" no longer has access.

I have tried assigning various permissions for all these users and shared folders but can only ever set permissions on folders for users who are designated on the particular computer where the folder originated from, i.e. when i try to set permissions for who can view "Maries Documents" i only ever get a list of users and groups for that computer("SALES HOST").

Any suggestions would be greatly appreciated, if you require additional information then please say so.
 
For this workgroup configuration you will need:

On 'Sales-Host' you need to have all 4 accounts that match the various usernames and passwords. The you will be able to use the sharing and security features to do what you want.

On 'Design' it appears that you only need user David.

On Production, if I am interpreting correctly, you will need users Nev, Brian and David.

For more info see:
 
thanks very much for your help.

I tried this configuration today and in the most part succeeded.
 
Your frustration is that you are limited by the default group assignments.

smah's advice is correct. Check how you made entries for each user on a particular machine. Make certain you disable 'Guest' priviliges on each machine.

smah focused essentially on your ability to apply NTFS permissions. I believe that both he and I share some misgivings about more elaborate schemes for local computer policy through the management snap-ins. It can be a maintenance nightmare. NTFS permissions on a user basis is already a maintenance nightmare for you. What happens if Ev or David quit? (those are examples, I am not picking on either individual)

I would review quite seriously what security concerns you have. It may be true that using password protection on folders or individual files is a saner approach than either NTFS permissions or Group Policy.

See comments made in a recent thread, something like "How do I password protect a Folder?" for ideas. You can use the Search feature at the top of the Forum, search for "password folder".

Best wishes.



 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top