can this be done easily



Hi,

I have a AD network with 3 2003 DCs. Most of our workstations are attached to the domain while only 40 PCs are non-domain machines.

What I would like to do is to allow all non-domain PCs to be able to access one shared folder in one of the member server within the domain using one particular user account.

I created a group called nondomainuser and put a newly created user account into the group. I removed this user from the domain users group so it only belong to the nondomainuser group. On the shared folder, I setup the Share/NTFS permission so that only the nondomainuser group have read access to it. With this setup, the user is able to access the shared folder without problem. However, this account is also able to access shared folders that are accessible by the members in the domain users group which is something I don't want. The thing that I don't understand is this user account is not a member of the domain users, but he is still able to access shared folders that are for members of the domain users.

Can someone advice me if there is any simple solution for such problem?

Thanks

OM
.



Relevant Pages

  • Re: Can this be done without affecting current configuration
    ... access one shared folder in one of the member server within the domain ... I removed this user from the domain users group so ... is this user account is not a member of the domain users, ...
    (microsoft.public.windows.server.security)
  • Can this be done without affecting current configuration
    ... What I would like to do is to allow all non-domain PCs to be able to access one shared folder in one of the member server within the domain using one particular user account. ... this account is also able to access shared folders that are accessible by the members in the domain users group which is something I don't want. ...
    (microsoft.public.windows.server.security)
  • RE: Elevated Permissions on Vista Workstation!!
    ... You can access the shared folder with a domain user account that does not ... have the explicit ALLOW access permission on a Windows Vista client. ... please verify the access permission of that user account on the ...
    (microsoft.public.windows.server.sbs)
  • Re: XP Home
    ... >> home computers which can not access the shared folders on the SBS server ... What is the user account which you used to access the shared folder? ... please paste it in the newsgroup. ...
    (microsoft.public.windows.server.sbs)
  • Re: Can this be done without affecting current configuration
    ... I removed this user from the domain users ... group so it only belong to the nondomainuser group. ... user is able to access the shared folder without problem. ... user account is not a member of the domain users, ...
    (microsoft.public.windows.server.security)