Koldov Posted May 24, 2017 Posted May 24, 2017 Hi All, After disabling SMB v1 and having no scan to shared folder available for a couple of weeks, we finally have a new MFD which uses SMB v2. Hooray! However, it made me think about the MFD's permission to that folder. It appears that the old MFD was given admin credentials to scan into the folder and I'm not happy about that... I tried setting up a new SCAN user in AD and putting those details into the MFD, but it is not working. The SCAN user is a member of Domain Users only and just has write permission on the folder, does it need anything else?
jthompson Posted May 24, 2017 Posted May 24, 2017 Check the share permissions for the share that it's using (i.e. not the folder's security permissions). You may need to add the user account in there and give it more than just 'Read'. 1
ollyyllo Posted May 24, 2017 Posted May 24, 2017 (edited) If the folder your scanning to is a subfolder, the folders above need to have 'list folder contents' for the SCAN user. That's if you have set the write permission only on that folder. Edited May 24, 2017 by ollyyllo 1
AndyE Posted May 24, 2017 Posted May 24, 2017 What jthompson said sounds right, if it's not that then be sure to check the path properly. If it asks for an IP address/host name separate from the 'Folder Path' then do not give the folder path in the format \\server\share, instead just list the share name like below. 1
Koldov Posted May 26, 2017 Author Posted May 26, 2017 Thanks for the help guys... I ended up with this set of permissions. It wasn't until I got to 'modify' on the sub-folder that it actually worked though. Think I need a refresh on basic permissions though as I still find them confusing. I'd tried various permutations and it all got a little muddled, maybe I could get away with less but this is what worked so I left it there (at least I didn't have to give full permissions).
jthompson Posted May 26, 2017 Posted May 26, 2017 Just as an aside, another way to do it would be to create a share on your scan folder, so that your MFD can then access just that folder directly without needing to use your main Staff$ share to get to it. That ought to mean you then don't have to have any permissions listed for the scan user on the top level, just on the folder itself. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now