Re: Web Server 2003 File Sharing

From: Scott Napolitan [MSFT] (scottnap_at_online.microsoft.com)
Date: 02/03/05


Date: Thu, 03 Feb 2005 08:47:30 -0800
To: Dominic Messenger <dmessenger@verdantsys.com>

Dominic Messenger wrote:
> I've tried removing Deny Everyone, but this doesn't seem to help.
>
> Although I made several changes to the Security Policy, the main
> change was to disable several old accounts and change the
> Administrator account name.
> I then went into a previous file share and tried to replace it with
> the new administrator credentials (new name, old password) and now I
> can't connect.
>
> Any pointers ? Is there a specific set of policies I need to set on
> the Admin account to get this to work ? I am pulling my hair out.
>
> Dominic Messenger wrote:
>
>>I have a Web Server on the internet, firewalled so that only Port
>>80/443 are available, but everything is available to known IP ranges.
>>
>>Up until recently, we could share a drive on the server with machines
>>in the known IP ranges. Then, we applied some policy changes to lock
>>down IIS, and the shares stopped working.
>>
>>Can anyone give me any pointers as to what Local Security Policy
>>settings I need to enable to get file sharing working again. We can
>>create accounts on the server for each user, and apply specific
>>policies, but it is just knowing which ones.
>>
>>We have denied Everyone access on the share. Is this important ?
>>
>>Regards
>>
>>Dominic
>
> The Deny Everyone is probably your problem. Deny overrides any
> explicit
> permission granted so the only one that should be able to access this
> is
> the administrator. What you might want to consider instead is denying
> access to the IUSR_COMPUTERNAME account where COMPUTERNAME is the name
> of the server. This will effectively restrict any anonymous access.
> The best bet is to consider simply not granting access to whomever you
> don't want to get at the share. This way you don't have to explicitly
> deny anyone.
In general you should be able to connect as the Administrator no matter
what, assuming of course that that account is not disabled and that you
are typing the correct password. Are you unable to connect to the share
as an administrator? Can you access the share locally (at the console)?

-- 
Legal Disclaimer:
This posting is provided "AS IS" with no warranties, and confers no 
rights. Use of included script samples are subject to the terms 
specified at http://www.microsoft.com/info/cpyright.htm  Please do not 
send e-mail directly to this alias. This alias is for newsgroup purposes 
only.


Relevant Pages

  • Re: WinXP Pro "Users" Group Restrictions Affect Administrator Accounts
    ... >then removed the Users group from the permissions. ... >administrator password that's in the text file, ... under an account with just regular User ... >Thanks for the tip on the special deny group. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: WinXP Pro "Users" Group Restrictions Affect Administrator Accounts
    ... >then removed the Users group from the permissions. ... >runas to run individual programs with administrator privileges. ... >Outlook, under an account with just regular User privileges, as these ... >Thanks for the tip on the special deny group. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Windows 2000 Server Can access Windows Update Site.
    ... Administrators and Services were already in the security policy. ... The user trying to do the updates is a Domain Administrator. ... Verify the Local Administrator and Service account are added to the ... >> All machines are on the SAME LAN. ...
    (microsoft.public.windowsupdate)
  • Re: Win2003 Web Edition File Sharing
    ... Although I made several changes to the Security Policy, ... Admin account to get this to work? ... >> I have a Web Server on the internet, ... > The Deny Everyone is probably your problem. ...
    (microsoft.public.windows.server.general)
  • RE: Windows 2000 Server Can access Windows Update Site.
    ... me on 1 server, the other one I had problem with got the update software but ... Verify the Local Administrator and Service account are added to the ... "Impersonate a client after authentication" security policy. ...
    (microsoft.public.windowsupdate)

Loading