Re: domain vs workgroup...



Yes, with a single server using local user accounts, you can lock down
access to folders and shares. The issue here is that the security principals
are LOCAL to the server, meaning none of the 15-20 PCs will share that same
local account database (there is a "workaround," which I will mention).

I have a client who has about 30 users and they are still in a workgroup.
One day I would like to set them up on a domain, but I can't justify the
cost for doing that right now. They have been working fine in their
workgroup, so they are really going to need some convincing to pay me
several $100 to configure a new domain for them.

Because the client does not utilize an AD domain for user authentication and
is instead in a workgroup configuration, the local desktop user accounts
must have the same username and password as that of the user account on the
server. So that's why they all share the same username/password, ie,
everyone logs on locally as User1/password1 and the server also has the same
account created locally. This is how User1 from any desktop PC can access
any resource that User1 from the server has been given access to.

Yeah, this isn't the greatest setup from a security standpoint. And because
everyone shares the same account it's hard to track down who did what. But
if it's a small company where everyone works closely with each other, I
don't see a reason to get too paranoid about security.

So yes, what you are asking can be done. If the business owner is too cheap
to get Windows XP Pro, then he or she would probably not see the cost
justification in paying you to set up a domain. So in your situation, a
workgroup might be your only option.

--
Regards,

Martin X.
Microsoft Certified Systems Administrator: Messaging
Philadelphia, Pennsylvania, USA

"Mike" <mikey117@xxxxxxxxxxx> wrote in message
news:u1Gbo0uIIHA.1316@xxxxxxxxxxxxxxxxxxxxxxx
Can I set up a server in a workgroup type environment & share files, control
access to files, etc., just like in a domain environment?
I have a client who has 15-20 XP Home machines & has finally decided that
they need a server, as sharing files between 15-20 computers has become
quite a hassle!

--
The intelligent man wins his battles with pointed words.
I'm sorry -- I meant sticks. Pointed sticks.



.



Relevant Pages

  • Re: samba installed from scratch on fc9 doesnt work for me
    ... the 'workgroup' name in smb.conf should be the DOMAIN for all users ... service nmb start ... if I try to access without a password it says "server not using user ... level security and no password supplied". ...
    (Fedora)
  • Re: Hacking advice?
    ... How can I harden my computer or server to secure it from hackers? ... To secure your computer and prevent future security breeches, ... consider installing a first-rate internet security program: ... | it is still a part of the old workgroup: ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Win2k8 in a workgroup - share permissions
    ... subsequently change anything (domain name, server name, computer name, user ... In a workgroup you have to know all of the computers that have shared resources the user accesses and change the account on every one of them. ... As for setting NTFS security so that anybody has access and using share permissions to control access, that has so many bad security implications it's laughable. ...
    (microsoft.public.windows.server.security)
  • RE: workgroups
    ... My problem is that I would like to centralize my user accounts. ... > Are you confusing a Workgroup with a Domain? ... > each network resource. ... > and Windows 2000 Server products as long as the server is not configured as a ...
    (microsoft.public.windowsxp.general)
  • Re: Workgroup to Domain - Worth The Trouble?
    ... > just bought a nice shiny new server running Windows Server 2003. ... for example - I switched my PC from workgroup to domain and ... The benefits of a domain is *centralized* security and control. ... both a computer account and a user account is required to ...
    (microsoft.public.win2000.networking)

Loading