Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

How to set server2012 folder, LAN share setting permissions and server2012r2 file sharing permissions

2025-02-22 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Servers >

Share

Shulou(Shulou.com)06/01 Report--

Editor to share with you how to set server2012 folders, LAN sharing permissions and server2012r2 file sharing permissions, I believe most people do not know much about it, so share this article for your reference, I hope you can learn a lot after reading this article, let's go to know it!

WindowsServer2012 is a new generation of Microsoft file server operating system, various functions have been greatly enhanced, many enterprises have also used Server2012 as a file server to share files for LAN users to access. Then, how to give full play to the function of Server2012 in file sharing, which requires a detailed understanding of the steps of server sharing settings, and then give full play to the function of the operating system in the setting of file access permissions. For example, through the server login account to set access to different shared files, or through the Windows AD domain controller to set shared file access rights, and so on. The details are as follows:

Goal: to establish a shared folder, in which each user sets up his own subfolders, and each user only accesses his or her own authorized folder, and the user cannot see the unauthorized folder. Each user has a different disk quota, and there is an alarm for the disk configuration. Masks the specified file type for different users. Get rid of the worm. Monitor the usage of files in the shared folder.

1. Establish a total shared file\ share

\ share-- right-click (Properties)-share (menu)-Advanced sharing-(tick) share this folder-enter shared folder name-permissions-every-- (check) full control

\ share-- right click (attribute)-Security-Advanced-effective access (menu)-Select user-add domainusers group

\ share-- right (property)-Security-Advanced-permissions-(Point) prohibit inheritance-(select) convert inherited permissions to explicit permissions for this object.

\ share-- right click (attribute)-- Security-- Advanced-- permissions-- keep system and administrators user groups in the permission entry

\ share-- right-click (property)-- Security-- Advanced-- (tick) to replace the items of all child objects with inherited permissions from this object.

\ share-- right (attribute)-Security-Advanced-permissions-(Point) add-Select principal-add domainusers group (OK)-apply to (only this folder)-basic permissions (check) full control

Apply-- determine

Note: if there are already files in the subfolder, and then give the subfolder permission to a domainuser, then thisuser can not see the existing files. Solution: 1, make a copy of the existing file; 2, the properties in the subfolder-- Security-- Advanced-- tick-- the permission items inherited from this object can replace the projects of all sub-objects-- application.

When the share folder is set, you must not right-share-- (Properties)-Security-Advanced-(tick) to replace the items of all sub-objects with the permission items inherited from this object, so that the permissions of all domainuser in the subfolders within the share will be lost.

2. The user cannot see the folder without permission

Server Manager-File and Storage Services-sharing-Select Directory (right-click) Properties-Settings-(tick) enable access-based enumeration.

3. Establish shared folders and user accounts in batches and grant permissions in batches

Create a user list file, username.txt. Each user list has a single line with no spaces in front of it. Create folders and accounts in batches based on this file, as well as empower the accounts.

3.1powershell

3.2 > cdc:\ share// go to the established shared folder directory to operate

3. 3 > for/f%ain (c:\ username.txt) domkdir%a

3. 4 > for/f%ain (c:\ username.txt) donetuser%apassword/add// runs on ad

For/f%iin (c:\ username.txt) docaclsc:\ share\% i/e/g%i:f

For/f%iin (c:\ username.txt) donetuser%i

4. Disk quota

4.1 install file server quota, deworming, network files and other functions

Server Manager-manage-add roles-File and Storage Server-File and iscsi Services-(tick) File Server Resource Manager, Network File CranchCache, data deletion duplicates. -- next-- installation

4.2 quota management

Server Manager-tools-File Server Resource Manager-quota Management-quota template-(right) create quota template-template name-Space size limit-soft and hard limit-threshold-determine

Soft limit: users can break through the limit control, notify the administrator through the threshold, and monitor mainly.

Hard limit: users cannot break through the limit. They can notify the administrator in advance through the threshold, and control the space mainly.

Server Manager-tools-File Server Explorer-quota Management-quota-(right) create quota-enter quota path-(tick) automatically apply templates in existing and new subfolders and create quotas. -- Select the type of quota (you can also customize it)-- create

4.3 File masking

File server is used to store document files, non-document file screen. There are different shielding strategies for special directories.

(1) shielded templates that only store documents and compressed packages

Tool-File Server Explorer-File screen Management-File screen template-(right) create file screen template-template name-active screen-Select options with office and text exceptions checked-set alarm trigger to network administrator-and set to generate report.

(2) tools-- File server explorer-- File screen management-- File screen management-- (right) create file screen-- Select path amure-Select template (custom)-- create file mask exception in path a-- Select file type or.

4.5 Storage report Management

Tools-File Server Explorer-Storage report Management-(right) schedule new report tasks-

Settings: report name-report data type (tick select)-generate report format-schedule-send email or file name.

4.6 deworming

Dashboard-File and Storage Services-Volume-selected disk (right)-right (configure data deletion replication)-(tick) enable data deletion replication-set repeat schedule-(tick) start background optimization-(tick) enable throughput optimization.

Deworming command:

> get-command | where {$_ .name-match "dedup"}

> start-dedupjob

> get-helpstart0dedupjob

4.7 set access to shared files with special server sharing file management software

Although the access to shared files can be set through the user account of the Windows operating system or the Windows AD domain controller, it is always impossible to achieve fine control over the access to shared files. In particular, it is not possible to only read shared files and prohibit copying shared files, only to modify east-west files to prohibit deletion of shared files, and only to open shared files and prohibit saving as local diskettes. And prevent dragging shared files, printing shared files and other behaviors to prevent shared files from leaking out. In this case, it needs to be realized with the help of special LAN shared file management tools.

For example, there is a "general trend to LAN shared file management system" (download address: http://www.grabsun.com/gongxiangwenjianshenji.html). After installing on the file server, you can automatically scan all the shared files on the LAN and all the access accounts of the server (including the account of the Windows domain controller), and then you can set up different access accounts for sharing files on different servers. You can allow reading of shared files but prohibit copying of shared files, allow modification of shared files to prohibit deletion of shared files, allow opening of shared files and prohibit saving as local disk, or organize the behavior of dragging or printing shared files. As shown in the following figure:

In addition, the log of local area network users accessing shared files can be recorded in detail through this system, which is convenient for administrators to check and audit afterwards.

The above is all the contents of the article "how to set up server2012 folders, LAN sharing permissions and server2012r2 file sharing permissions". Thank you for reading! I believe we all have a certain understanding, hope to share the content to help you, if you want to learn more knowledge, welcome to follow the industry information channel!

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Servers

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report