littlenblonde Posted August 6, 2021 Posted August 6, 2021 I have recently attached some Macs to our network. I have successfully managed to get Windows domain users logged on with their windows credentials. The problem I'm experiencing is that students are able to see all online computers and servers and are able to access various files on the servers. I have looked at the File Sharing options but these only seem to restrict local accounts on the macs rather than the windows users. Does anyone have any ideas other than to put restrictions on each of the files on the servers directly?
3s-gtech Posted August 6, 2021 Posted August 6, 2021 Is it file shares on the servers that they can see? What are the share permissions?
chaplic Posted August 6, 2021 Posted August 6, 2021 your problem isnt the client (mac) its your share/ file permissions are wrong. You are also a bad download away from being cryptolockered. 1
Jcx500 Posted August 6, 2021 Posted August 6, 2021 (edited) As others have said it will be your file permissions. Get those locked down ! Edited August 6, 2021 by Jcx500
littlenblonde Posted August 6, 2021 Author Posted August 6, 2021 Thank you for your replies. I thought as much but it's always good to have it confirmed. I'll get onto the permissions straight away. I haven't given students access yet as I wanted to make sure all security issues were sorted first. Thanks again.
joewb Posted October 15, 2021 Posted October 15, 2021 If you are running Windows server for Mac and aren't 100% sure on your permissions, I'd take a look at Acronis software, it allows the Mac users to connect over AFP which is much less of a headache to manage!
Koldov Posted October 15, 2021 Posted October 15, 2021 Can someone expand on this just a little...? We only have one Mac on site (and it is the Headmasters), I didn't have much time to set it up or look into what he could or couldn't see. It's bound to our Domain and I made shortcuts to the shares he needs and that's all I was able to get done before he started asking for it. It was a good few years ago now (feels like a lifetime) and obviously I only did it once and promptly forgot all about it... As far as I can see, he is a member of 'Apple Mac SMB Share Access' a Global Security Group. He is the only 'Member' and it is not a 'Member Of' anything. He can access the shares through membership of various other security groups via his Domain Log-on credentials and the only place I can find the 'Apple Mac SMB Share Access' Security Group having any permissions appears to be in his H:\ drive (personal folder on the server). Sound good?
psydii Posted October 20, 2021 Posted October 20, 2021 That sounds fine. Not entirely sure why you have that security group at all though*. Given the available facts (1 its working, 2 only the HM is a member and it isn't a member of anything else, 3, only one share makes use of it in its acls) best leave it alone. If the HM on their mac can't access files and folders in shares you wouldn't expect them too (for example C$ or "IT Tech's share") then you've not got the issue that the OP had where it sound like they have "everyone/full control" on all shares and file/folder permissions, using only Group Policy to limit what Windows/explorer would present to the user. *Just remembered: once upon a time macos/osx needed to be able to have access to the parent folder before it could mount a subfolder to which it had an appropriate NTFS read/write ACE. Been a while since I thought about it, not sure if that is still a requirement. 1
Koldov Posted October 20, 2021 Posted October 20, 2021 *Just remembered: once upon a time macos/osx needed to be able to have access to the parent folder before it could mount a subfolder to which it had an appropriate NTFS read/write ACE. Been a while since I thought about it, not sure if that is still a requirement. Yes! That's exactly why I thought about rechecking mine when I saw this thread as I seem to remember coming across something like that when I first set-up the shares.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now