Network Shared Files/UNC

From: Mark (anonymous_at_discussions.microsoft.com)
Date: 09/16/04


Date: Thu, 16 Sep 2004 12:25:47 -0700

Good Afternoon,

I was just wondering if anyone knew why a user of ours
gets "access to the resource" + \\servername + "has been
disallowed." when a user tries to put \\servername in the
address bar of Internet Explorer 6.0. I know that it is a
Group Policy setting and not just permissions to the
server. If you could tell me which one it is, I'd
appreciate it very much. Thanks. Also, we have had
issues regarding our network security. Below is our
Deployment:

1. One Domain
2. One Domain Controller hosting the one domain
deployment -- no backup DCs
3. Created a OU named DemoUsers
4. Placed the Demo User within that OU
5. Applied GPO to the OU -- User Section only
6. GPO settings are not inherited from the domain GPO
7. GPO settings are using Very Strict Restrictions

With this deployment, even though the user is prevented
from navigating to the Network through the Network
Neighborhood and Windows Explorer, the user is still able
to navigate within our network and accessing the Shared
folders of our servers by just running Notepad and going
to File | Save and entering in \\servername. Is there a
way for me to prevent this access using GPOs or is there
another way of tightening security so that the Servers are
hidden from this user. I can just apply security
permissions on the shared folders on the servers but I
would like access to the shared folders restricted not
user explicit. For example, if a user on that server were
to share a folder that was important that contained
his/her personal information in there and did not set
security permissions to exclude certain users, then the
demo user can in fact delete that folder or open it. If
anyone can help, it would save me a lot of trouble and
hopefully keep my sanity in check.

Mark



Relevant Pages

  • Re: ZONES VIA GPOs
    ... When I am trying to modify Security Zone ... which needs Enhaced Security Settings to XP ... I know that there is this option on W2K2 Servers, ... create the GPO on one of the servers. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: gpo security filtering
    ... OU of computer objects and create a security group and add a subset of the ... If I leave off the security group of computer objects and add authenticated ... users will this gpo apply to any outside users or only the computer objects ... I created a security group with the servers I want windows updates ...
    (microsoft.public.windows.group_policy)
  • Re: Program that hides apps and files
    ... > Seems there is a program available from the hacker sites ... > directory in folders that are not normally available to ... > labs, and servers. ... IT Security can see the illicit traffic, ...
    (alt.computer.security)
  • Re: how to apply w2k baseline template to w2k servers under w2k3 AD?
    ... But you should be fine importing them and link them to appropriate OU. ... separate OU for the W2K servers that is... ... but how to manage the security to w2k servers using ... > GPO? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Network Shared Files/UNC
    ... Windows Server MVP ... > issues regarding our network security. ... GPO settings are not inherited from the domain GPO ... > folders of our servers by just running Notepad and going ...
    (microsoft.public.win2000.active_directory)