ExamNotes.net  -  IT certification portal

ForumsCertResearchTop sitesNewslettersFree email
HomeRegister
Exams Notes
Practice exams
Exam games
Questions by email
Online training
Training videos
College degrees
Boot camps
Book store
Links directory
Tell a friend
For webmasters

CompTIA Exam Vouchers
Save money on CompTIA exams
Question of the day
Sign up to receive
interactive practice questions
for MCSE, CompTIA
Cisco and other exams
TestKing
Get MCSE, MCSD, CCNA, CCNP,A+, N+ and many more

* ExamSheets *
Guide for Success!
Actual Questions & Answers
MCSE, MCSD, A+ ,CCNA, CCNP
Oracle 8i, Oracle 9i

Online practice tests

Certification sites

Online university

Online college

Online education

Distance learning

Software forum

Server administration forum

Programming resources






This is interesting: Free IT Magazines | Databases help forum



General discussions > General Discussion > PLEASE help me with this...

Show a Printable Version
Email This Page to Someone!
Receive updates to this thread






Author PLEASE help me with this...
Ormewood
Junior Member
M




Registered: Jun 2001
Location: Atlanta
Country: United States
State:
Certifications: none
Working on: MCSE

Total Posts: 6
PLEASE help me with this...

I know this is a basic question, but I'm working on my first certification, and basic is where I am at the moment.

OK...here is a quote from Jerald Divley's "PassIT" (for 70-215):

"NTFS permissions cannot be applied to shares."

And later in the same text:

"Know that NTFS permissions are used for local file-level security and cannot be applied to a share."

Meanwhile, here's this quote from p. 195 of Microsoft's 70-215 cerification textbook:

"When users gain access to a shared folder on an NTFS partition, you should use either share rights or NTFS permissions but not both."

In fact, it goes on to say:

"NTFS permissions are preferred since permissions can be set on both files and folders."

So what is the deal here? Is the cram book by Jerald Divley just wrong, or am I misunderstanding something basic? Can you apply NTFS permissions to a share, or not?

__________________
=There are no differences but differences of degree between different degrees of difference and no difference.=

Report this post to a moderator

Old Post 08-26-02 01:37 AM
Ormewood is offline Click Here to See the Profile for Ormewood Click here to Send Ormewood a Private Message Visit Ormewood's homepage! Add Ormewood to your buddy list Find more posts by Ormewood    Ormewood's ICQ status       Send an AIM message to Ormewood Reply w/Quote Edit/Delete Message IP: Logged
twister166
I am dizzy...




Registered: Jul 2002
Location: FL, USA
Country: United States
State:
Certifications: A+, N+, Srv+, MCSE 2K, MCSA, CCNA, CCDA, CTT+ (CBT)
Working on: CTT+ (video), CCNP, CCDP, CISSP

Total Posts: 1048

Let's do it in reverse, if you want to access a file in an NT/2000 server. Assume that you have all the networks and user accounts setup.

You will need to access the server via the "share" which is a resource on the server created for access. It can be a folder, printer, CD or whatever the server has controll and can share. We will focus on the Folder at this moment.

So, if you would to share that "FOLDER", under FAT16/32, you can only assign the permission to the share. If you are under NTFS, you can then assign the permissions to the sub-folder and/or files.

The permission to access an NTFS permission with Share permission is most restrictive.

Example, assume remote access not local access (means you are getting the resource from network in infront of the server) if you have a share is read only, even the NTFS permission is everyone/full control, you will only have read.

Oppositely speaking, if your Share is eveyone-full control and NTFS is read, you will have read.

Hope this clear it up.

Report this post to a moderator

Old Post 08-26-02 02:11 AM
twister166 is offline Click Here to See the Profile for twister166 Click here to Send twister166 a Private Message Add twister166 to your buddy list Find more posts by twister166 Reply w/Quote Edit/Delete Message IP: Logged
Tech Ranger
On A Mission
M




Registered: Feb 2002
Location: Brooklyn, New York
Country: United States
State:
Certifications: MCSA, MCP(210,215,217,218,219), Server+, Network+, I-Net+, A+
Working on: MCSE (216 at the moment)

Total Posts: 5309

NTFS is a file system. This file system allows you to do security at the volume, folder, and file level. If a volume is formatted with NTFS, you can apply NTFS permissions. These permissions apply irrespective of whether you share out the resource. The share permissions is another layer of security. The share permissions apply irrespective of the underlying file system. The most common approach to administering permissions is to leave the share permissions at the default everyone/full control and apply security to NTFS volumes or folders. These permissions typically are assigned to groups. Users inherit the permissions as a consequence of group membership. In the event that both share and NTFS permissions are applied to a resource, the more restrictive permissions take effect.

__________________
The Computer is a creation of man. Man is a creation of God! -
Joe from Brooklyn

Report this post to a moderator

Old Post 08-26-02 04:07 AM
Tech Ranger is offline Click Here to See the Profile for Tech Ranger Click here to Send Tech Ranger a Private Message Add Tech Ranger to your buddy list Find more posts by Tech Ranger Reply w/Quote Edit/Delete Message IP: Logged
lardie
Phantom Sig Changer




Registered: Jul 2002
Location: Bristol
Country: United Kingdom
State:
Certifications:
Working on: MCSE 2K

Total Posts: 121

Have to admit this is one area that confuses me aswell.

So when applying permissions to NTFS and Shares the most restrictive applies !

And when dealing with a user in multiple Groups with different NTFS permissions the least resrictive applies, assuming that no share level permisions are set.

And if a user in multiple groups with different NTFS permissions access's a Share with permissions set the effective permission would be the most restrictive of

Least restrictive NTFS permission vs Share permission ?

Have I described that clearly, and more importantly is it right ?

Man my head hurts now

__________________
Not another sig change sheesh

Last edited by lardie on 08-26-02 at 11:31 AM

Report this post to a moderator

Old Post 08-26-02 11:18 AM
lardie is offline Click Here to See the Profile for lardie Click here to Send lardie a Private Message Add lardie to your buddy list Find more posts by lardie Reply w/Quote Edit/Delete Message IP: Logged
Tech Ranger
On A Mission
M




Registered: Feb 2002
Location: Brooklyn, New York
Country: United States
State:
Certifications: MCSA, MCP(210,215,217,218,219), Server+, Network+, I-Net+, A+
Working on: MCSE (216 at the moment)

Total Posts: 5309

If you have read NTFS permissions to a folder, you cannot modify that folder. So I create a folder and give you read permissions. Next week I decide to share out the folder and I leave the default everyone/full control share permission in place. You access the folder remotely. The system opens the door wide open for you to access the folder. you open it. No problem. Now you try to create a file. The share permissions say go ahead, no problem here. Next, since the folder is on an NTFS volume, the acess control list and access control entries are checked. It is determined that you only have the read permission. But, your honor, my client has the full control share permission. Motion denied, counselor. I couldn't give a damn about his share permissions. I am presiding over an NTFS volume. Whether this volume or its folders are shared or not is of no concern to me. Take a walk.
Now, with respect to permissions inherited by group memberships and permissions granted directly. Permissions are cumulative. If you get Read from 1 group and Write from another, you have read and write. The exception to this is the Deny factor. If a permission is Denied, it overrules all other permission settings.
Here it is in a nutshell:
Add up all your NTFS permissions, subtract any Denies.
this is your effective NTFS permission.
Add up all your share permissions. Subtract any denies. This is your effective share permission.
The more restrictive of the 2 is your overall effective permission to a resource if you are accessing that resource over the network.

__________________
The Computer is a creation of man. Man is a creation of God! -
Joe from Brooklyn

Last edited by Tech Ranger on 08-26-02 at 11:26 PM

Report this post to a moderator

Old Post 08-26-02 12:04 PM
Tech Ranger is offline Click Here to See the Profile for Tech Ranger Click here to Send Tech Ranger a Private Message Add Tech Ranger to your buddy list Find more posts by Tech Ranger Reply w/Quote Edit/Delete Message IP: Logged
lardie
Phantom Sig Changer




Registered: Jul 2002
Location: Bristol
Country: United Kingdom
State:
Certifications:
Working on: MCSE 2K

Total Posts: 121

Cheers Tech Ranger cleared that up nicely yer onor

__________________
Not another sig change sheesh

Report this post to a moderator

Old Post 08-26-02 12:20 PM
lardie is offline Click Here to See the Profile for lardie Click here to Send lardie a Private Message Add lardie to your buddy list Find more posts by lardie Reply w/Quote Edit/Delete Message IP: Logged
Ormewood
Junior Member
M




Registered: Jun 2001
Location: Atlanta
Country: United States
State:
Certifications: none
Working on: MCSE

Total Posts: 6
Thanks...let me rephrase the question, though

OK...

Suppose you have a shared folder on an NTFS volume.

I understand that if you had subfolders and files in this folder, and if NTFS permissions were assigned to these subfolders and files, that the most restrictive of the share permissions and NTFS permissions would apply to the subfolders and files.

My question is this: Can you apply NTFS permissions to the shared folder itself , rather than to the subfolders and files? I understand that this probably isn't a desirable thing to do; I'm just trying to make sense of Jerald Divley's statement that "NTFS permissions cannot be applied to shares".

__________________
=There are no differences but differences of degree between different degrees of difference and no difference.=

Report this post to a moderator

Old Post 08-26-02 12:23 PM
Ormewood is offline Click Here to See the Profile for Ormewood Click here to Send Ormewood a Private Message Visit Ormewood's homepage! Add Ormewood to your buddy list Find more posts by Ormewood    Ormewood's ICQ status       Send an AIM message to Ormewood Reply w/Quote Edit/Delete Message IP: Logged
Tech Ranger
On A Mission
M




Registered: Feb 2002
Location: Brooklyn, New York
Country: United States
State:
Certifications: MCSA, MCP(210,215,217,218,219), Server+, Network+, I-Net+, A+
Working on: MCSE (216 at the moment)

Total Posts: 5309

When you set NTFS permissions for a folder, by default the perms are inherited by all files and subfolders. You can override this setup by unchecking the box at the subfolder or file which says "Allow inheritable permissions from parent to propogate to this object".

__________________
The Computer is a creation of man. Man is a creation of God! -
Joe from Brooklyn

Report this post to a moderator

Old Post 08-26-02 11:24 PM
Tech Ranger is offline Click Here to See the Profile for Tech Ranger Click here to Send Tech Ranger a Private Message Add Tech Ranger to your buddy list Find more posts by Tech Ranger Reply w/Quote Edit/Delete Message IP: Logged
All times are GMT.
Post new thread   Post reply

Featured site: MCSE, MCSD, CompTIA, CCNA training videos



Forum Jump:
Rate This Thread:
Forum Rules:
Who Can Read The Forum? Any registered user or guest.
Who Can Post New Topics? Any registered user.
Who Can Post Replies? Any registered user.
Changes: Messages can be edited by their author.
Posts: HTML code is OFF. Smilies are ON. vB code is ON. [IMG] code is ON.
 

ExamNotes forum archive


Powered by: vBulletin 2.2.8
Copyright ©2000, Jelsoft Enterprises Limited.

  Free Braindumps | mcse braindumps