Jump to content

Mac users with Windows credentials can access server files


Recommended Posts

Posted

I have recently attached some Macs to our network. I have successfully managed to get Windows domain users logged on with their windows credentials. The problem I'm experiencing is that students are able to see all online computers and servers and are able to access various files on the servers.

 

I have looked at the File Sharing options but these only seem to restrict local accounts on the macs rather than the windows users. Does anyone have any ideas other than to put restrictions on each of the files on the servers directly?

Posted
your problem isnt the client (mac) its your share/ file permissions are wrong. You are also a bad download away from being cryptolockered.
  • Thanks 1
Posted

Thank you for your replies. I thought as much but it's always good to have it confirmed. I'll get onto the permissions straight away. I haven't given students access yet as I wanted to make sure all security issues were sorted first.

Thanks again.

  • 2 months later...
Posted
If you are running Windows server for Mac and aren't 100% sure on your permissions, I'd take a look at Acronis software, it allows the Mac users to connect over AFP which is much less of a headache to manage!
Posted

Can someone expand on this just a little...?

 

We only have one Mac on site (and it is the Headmasters), I didn't have much time to set it up or look into what he could or couldn't see.

 

It's bound to our Domain and I made shortcuts to the shares he needs and that's all I was able to get done before he started asking for it.

 

It was a good few years ago now (feels like a lifetime) and obviously I only did it once and promptly forgot all about it...

 

As far as I can see, he is a member of 'Apple Mac SMB Share Access' a Global Security Group. He is the only 'Member' and it is not a 'Member Of' anything.

 

He can access the shares through membership of various other security groups via his Domain Log-on credentials and the only place I can find the 'Apple Mac SMB Share Access' Security Group having any permissions appears to be in his H:\ drive (personal folder on the server).

 

Sound good?

Posted

That sounds fine. Not entirely sure why you have that security group at all though*. Given the available facts (1 its working, 2 only the HM is a member and it isn't a member of anything else, 3, only one share makes use of it in its acls) best leave it alone.

 

If the HM on their mac can't access files and folders in shares you wouldn't expect them too (for example C$ or "IT Tech's share") then you've not got the issue that the OP had where it sound like they have "everyone/full control" on all shares and file/folder permissions, using only Group Policy to limit what Windows/explorer would present to the user.

 

*Just remembered: once upon a time macos/osx needed to be able to have access to the parent folder before it could mount a subfolder to which it had an appropriate NTFS read/write ACE. Been a while since I thought about it, not sure if that is still a requirement.

  • Thanks 1
Posted
*Just remembered: once upon a time macos/osx needed to be able to have access to the parent folder before it could mount a subfolder to which it had an appropriate NTFS read/write ACE. Been a while since I thought about it, not sure if that is still a requirement.

 

Yes! That's exactly why I thought about rechecking mine when I saw this thread as I seem to remember coming across something like that when I first set-up the shares.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...