Re: Restricting remote access
- From: "Zardoz1" <zardoz1@xxxxxxxxxxxxxxxxxxxxx>
- Date: Sun, 3 Dec 2006 12:56:59 -0500
"Lanwench [MVP - Exchange]"
<lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:uaBPcqvFHHA.1080@xxxxxxxxxxxxxxxxxxxxxxx
In news:uGV2mhvFHHA.3976@xxxxxxxxxxxxxxxxxxxx,
Zardoz1 <zardoz1@xxxxxxxxxxxxxxxxxxxxx> typed:
Thanks for your great ideas. (This is the second response - the other
disappeared into a bloghole on the other side of the universe)
Hmmm. A partition? Why not a folder/share for accounting, and use NTFS to
secure it? A disk partition doesn't reflect any sort of security barrier.
Understand, but this is more psychological - I always make important
partition Drive letters the same as mapped drive letters - avoids confusion.
When I'm setting up a server, I don't use the Domain Users or
Authenticated Users groups to assign permissions - I create a security
group called something logical (Companyname Users) and use that. I also
use other groups (Accounting, Management, whatever) to grant permissions
to their relevant shares. I also make all my own/custom shares hidden from
browsing by using SHARENAME$ .
Excellent idea, will implement.
In this situation, if you have a user who needs access only to Accounting,
you just put her in the Accounting group - and not the Companyname Users
group. It doesn't matter whether she's using VPN or logging in directly at
a workstation, or logging in remotely via RD to a workstation. All she
will get access to is the Accounting share, no matter where she is.
Agree ordinarily, but she is a contractor not an employee, she doesn't have
a workstation on the local lan. Hence the VPN. She will use her own
workstation and accounting software, accessing the accounting data files
remotely. Should the untoward happen, we will have multiple backups as
recent as the previous day.
I'd also suggest using RD (via the RWW page) rather than having her accessAs above, I do agree - but in the absence any alternative - VPN seem the be
the files directly over the VPN connection....it's a lot more efficient,
isn't likely to corrupt any data if the connection has a hiccup. If the
files are a) largeish and b) critical to the business, everyone will be a
lot happier this way.
the only way. Is there a server side script that can run when this user logs
in and map a network drive?
.
- Follow-Ups:
- Re: Restricting remote access
- From: Lanwench [MVP - Exchange]
- Re: Restricting remote access
- References:
- Restricting remote access
- From: Zardoz1
- Re: Restricting remote access
- From: Lanwench [MVP - Exchange]
- Restricting remote access
- Prev by Date: Re: Trying to remove the Recovery Storage Group
- Next by Date: Re: Restricting remote access
- Previous by thread: Re: Restricting remote access
- Next by thread: Re: Restricting remote access
- Index(es):
Relevant Pages
|