Jump to content

Recommended Posts

Posted

Can anyone please help me

 

 

I have a network Server 2003 and XP clients, we are running a Group Policy on 5 separate OU's.

 

When the users are running any office application Word...

 

When you go to open and then click on the icon labelled "UP ONE LEVEL" it is showing files on the server.

 

Is there any way i can remove that icon or better still remove access to the server where there home directory is?

 

When they type in \\servername it is showing the shares and folders. Is there away i can stop users seeing the servers.

 

Steve

Posted

When my users go up a level they are just taken back to my computer.

I share the directory out on the server containing all the users files but they dont have any permissions on this. They then have permissions to their folder only. Because the system maps the drive everything works fine.

Posted
Yes i have the same setup but when i go up a level you can see the shares on the server. Can you suggest any ideas why it might be doing this
Posted
Infact if you continue to go up a level you eventually come to Entire network and can see all the servers
Posted

If you do not want users to be able to see shares on the servers you will need to create an administrative share by simply putting a $ at the end of the sharename.

 

Next make sure that the folders themselves have only permissions that are required for the job i.e.

 

Our assignments drive has the following;

Students : List, View, Read

Teachers: List, View, Read, modify

Admins: Full Control

 

The everyone group has been removed.

 

This generally means that the students can do nothing more that just read the contents of that folder.

 

There is a GPO setting that will stop UNC browsing so if you goto explorer and type in \\server-name\foldername it would be dissallowed.

 

I do not have it's location to hand but will find it and update this post

 

[edit]

 

Just had a thought, when you click open it should default to "My Documents" now ours are all redirected to thier home shares and if we select up on level it takes the to My Computer and then the desktop and no further. Are your My Docs folders redirected or not, that could be the issue.

 

[/edit]

Posted

Sounds strange to me. There is one setting that nags me here but im not sure if its relevant and that is something about connecting the user home directory to the root of the share or something along those lines.

 

Your definately not sharing the areas out individually? I have a drive letter mapped to them as well as my docs redirection which I assume you have?

Posted
Chris H - I have not got the Users directory shared i have the pupils indivudual folders shared. I have mapped there network drive
Posted

@Faza:

 

How have you mapped that pupils home drives via GPO or scripted i.e. Bat file ot vbs...??

 

[edit]

 

I agree with ChrisH our root folder is Students$ which only the admins have access to and then within that we have year group folders (NOT SHARED) and within those you get the individual students folders themselves shared as studentname$ with admins having full access and only the required students have full access also.

 

[/edit]

Posted
My problem is that i can still see the servers when i press up one level. I have not found the GPO setting to disable the UNC browsing.
Posted

faza: you need to establish that the permissions one the folders are correct, if everyone has access to the root share then they will be able to move around and yes eventually see all you have on the network.

 

I would take a single student login as them and check that you can traverse the network as you say above.

 

Next work from the students home share upwards checking the permissions not only on the share but the NTFS permissions also, I am sure you will see that there are permissions set that is allowing user

to go all the way up.

 

[edit]

 

Looking at the workflow I would assume that this is the scenario that you are following:

 

You creat a new user in AD and at the same time under the profile tab for the new user you point to \\server\studentsshare

 

Whent he new user logs on you are using some kind of login script to map the above home drive.

 

If this is the case them the user will be able to move all the way up.

 

You will need to create the user in AD and add the path to thier home share under the profile tab.

 

Then you will need to go into the GPO that affects the student and goto;

User Configuration --> Windows Settings --> Folder Redirection --> My Documents --> right Click --> Properties

 

The first option should be set to "Basic" and the second option should be "redirect to the users home folder".

 

Now by doing this when you click on the "Up one level" button it will take you to "My Computer" and then the Desktop and no further.

 

This would allow you to investigate UNC path mapping at your leisure and remove some pressure.

 

[/edit]

Posted
If i disable Computer Browser wont that effect some things on the netowrk. Like me the administrator i will not be able to see it listed will i?
Posted

If your using a machine with no Computer Browser service then yes, you wont see anything on the network.

 

Use a security filter on the GPO to selectively disable it on the computers you want.

Posted
If your using a machine with no Computer Browser service then yes, you wont see anything on the network.

 

Use a security filter on the GPO to selectively disable it on the computers you want.

Geoff

 

As i am new to the security filter could you please advise me on how to perform this?

 

Sorry to be a bother

Posted

1. Make a new group.

2. Add the machines accounts you want to apply the GPO to the group.

3. Go to the GPO in the GPMC

4. Remove the 'Authenticated Users' group from the security filters list.

5. Add the group you just made to the security filters list.

Posted

Ok, I have had a long battle with file sharing and permissions and here are a few things I have come across:

 

Some programs try to start at the root of the share, it they can't see the folders on the way to the redirected my documents they have an error. This affects Office and windows installer and Sims.net.

 

Office gives a permission error when going to save as, msi files give an invalid character in my documents and sims.net has an exception trying to create the My SIMS Documents folder in the home directory.

 

This was with a single user share when the users had no permissions on the folders preceding their home folder. My documents was redirected to their home folder.

 

This was fixed by splitting the share in to three main areas, administrators, staff and students. I then added the relevant groups to the folder permission on the folders required to reach their home folder from the root of that share. I added the group to "This Folder only" -> This bit is very important. It means that students and staff can see the folders of the other users in their group but attempting to access them results in a denied error (due to the this folder only).

 

Hidden shares aren't much help as they get shown when the drive is mapped anyway. I prefered when windows only told you the drive letter not the path to its share too.

 

Oh and disabling the network browsing never stopped anyone poking about the network, its trivial to get around. Disabling the browser service sounds more promising, but I'm not sure what else the relies on unc paths this might break.

  • 1 month later...
Posted

Could somebody advise me on if i am correctly setting the users area up.

 

1) I have a folder called users which is shared

2) Within that folder i have the different year groups folders which are also shared

3) Inside each year group folder is the pupils shared folder

 

Within the AD i specify the home folder to be h:\ and \\servername\pupilarea

 

 

Is this correct as still when the pupil selects up one level they are able to see the shares and then the domains. Can this be prevented

 

Can anyone please help

 

Any help would be very much appreciated!!!

 

Faza

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...