Re: Making a shared folder accessible to anyone from network



Hi Pete,

Let me preface this by saying that your application design is severely
limiting your marketability. I believe that most knowlegable administrators
would not like to install something that requires that they enable anonymous
access to a share, and most would be quite mad upon finding that an install
had done so without calling that fact out clearing in the pre-install
requirements
discussions/warnings. I myself would not install that application and if
found
after the fact without a forewarning I would militate against the vendor and
certainly put them on my blacklist to never do further business with in
future.

You need to look at the policy called
Network access: Shares that can be accessed anonymously
and its interaction with the policy called
Network access: Restrict anonymous access to Named Pipes and Shares
and the need to ACL the accessible with the Anonymous Logon principal
For a start search on the first mentioned policy in
http://www.microsoft.com/technet/security/prodtech/windowsserver2003/w2003hg/s3sgch04.mspx

It is the need to enable the second mentioned in order for the first
mentioned
policy to have effect that would cause most knowlegable administrators to
refuse permission to install for your application that requires this
capability.

Roger

"Pete" <no.one@xxxxxxxxxx> wrote in message
news:u4R8RfsvGHA.4460@xxxxxxxxxxxxxxxxxxxxxxx
Hello all!

I'm currently developing an application which should be accessible by
anyone on the Windows network. For this I'd like to create a share that
ANYONE on the network can access. The access only needs to be read-only.
For now I'd like to be able to define this on a Windows XP box.

I have tried editing the local security policy and tried to give anonymous
logon access to the share and the files in it. I don't want to use simple
file sharing, as it's not available when a computer is in a domain. The
solution should make the folder and its contents visible in all of these
scenarios:

- the computer with the shared folder is in a domain
- the computer with the shared folder is not in a domain
- the client computer is in a different domain than the computer with
the shared folder
- the client computer is not in a domain

Is this possible at all? In cases where all computers are in the same
domain, this problem does not exist, but there are all kinds of customer
IT-policies and in those cases the above scenarios might occur.

I'm sorry if this is to be found in a FAQ somwhere; I've googled for many
hours for a solution, but haven't been able to find one.

I'll be grateful for any information on this!

-Pete



.



Relevant Pages

  • Re: Terminal Server with SBS 2K3
    ... I am not sure how you configure your SBS fax, does the issue occur on every ... Do normal users try to install a network printer? ... Have you installed the Windows 2003 printer driver on ... |> "Prevent users from adding printers" group policy in the default domain ...
    (microsoft.public.windows.server.sbs)
  • Re: Using SUS to deploy patches, how to hide Windows update icon
    ... all notifications to users and doing silent installs. ... There are certain pros and cons to using this policy setting, ... If you set AU configuration to 4 (scheduled install) in the AU policy, ... reboot, but will not be able to postpone the reboot. ...
    (microsoft.public.windowsupdate)
  • Re: Possible security issue??
    ... I suppose that Group Policy could also be applying some file system ... unjoin your computer from the domain, reboot, and try to install the same ... I could only run it from the administrators (domain) ...
    (microsoft.public.win2000.security)
  • Re: Terminal Server with SBS 2K3
    ... The default domain controllers policy was "not defined" ... Do normal users try to install a network printer? ... when a normal user logs on the terminal server ... > the default domain controller policy to ensure that the "Prevent users ...
    (microsoft.public.windows.server.sbs)
  • Re: Software Installation Failing
    ... Windows Installer logging by setting the following policy: ... during the install a file will get created under ... > Assigned application KVS Enterprise Vault User Extensions 5.0 (flags ...
    (microsoft.public.win2000.group_policy)