doombadger Posted March 25, 2014 Posted March 25, 2014 Good Evening, It's just been flagged up to me that a member of staff can view all other members of staff's Windows file Server files on our AD integrated macs - Security on the Windows shared are set correctly - why is it that this user can completely 'bypass' windows security and view these files? and how can I stop this happening? I'd love to know..
TomCollins Posted March 25, 2014 Posted March 25, 2014 Is this isolated to the one member of staff or is it every user in that security group?
seawolf Posted March 25, 2014 Posted March 25, 2014 If users on the Macs can access other staff members home drive files then the Windows security permissions are NOT set correctly on the share(s), full stop. The Macs are just revealing an existing security flaw. Now, if they can just SEE the top level folders, but have no access to them that's a bit different.
doombadger Posted March 25, 2014 Author Posted March 25, 2014 Hi.. looks like all staff that logon to the macs are given 'read modify' rights in OS X on any folder on our staff shared area - which is a bit of an issue really! Looking at the window server share security in Windows on the folder it reads.. creator owner has special permissions system - full permissions domain User whose folder it is (eg BloggsJ) - full permissions Local Administrators (server) - full permissions Local Users (server) - Read Execute
doombadger Posted March 25, 2014 Author Posted March 25, 2014 I'm connecting using the directory utility mapping the home drive share as specified in AD - I wouldn't doubt that Windows security is the key to this, I'll give the 'effective permissions' tool a go and see what I can find..
FN-GM Posted March 25, 2014 Posted March 25, 2014 I would remove Local Users from the permissions. Its not needed. Not 100% without checking but i think the group Domain Users is a member of Local Users so that is what could be causing it.
seawolf Posted March 25, 2014 Posted March 25, 2014 (edited) Hi.. looks like all staff that logon to the macs are given 'read modify' rights in OS X on any folder on our staff shared area - which is a bit of an issue really! Looking at the window server share security in Windows on the folder it reads.. creator owner has special permissions system - full permissions domain User whose folder it is (eg BloggsJ) - full permissions Local Administrators (server) - full permissions Local Users (server) - Read Execute You really shouldn't have "Local Users (server)" with permissions to this share. This is the cause of the issue. EDIT: @FN-GM beat me to it. Edited March 25, 2014 by seawolf
doombadger Posted March 26, 2014 Author Posted March 26, 2014 Ok.. I've removed permissions for local users for the share - great that clears up the issue of viewing the folders, but I it has highlighted two other issues - one, users in the AD staff group now cannot access their drives at all and that the Windows Server now cannot browse Active Directory for me to add in the staff group to sharing permissions.
seawolf Posted March 26, 2014 Posted March 26, 2014 (edited) What version of Windows server are you using? We don't have local users permissions set on any shares and do not experience these issues, not have I seen them. We are on 2008 R2. Edit: What is the directory structure of your shares? How many levels down from the root of the drive are they? Edited March 26, 2014 by seawolf
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now