Re: How to restrict file access to Domain Computers Only



That of course is normally a great solution but in this case it sounds like
the file server is the domain controller which means ipsec could not be
implemented as an ipsec require policy on a DC will cause problems with the
domain member computers. Since it is may be a small network some else
mentioned that this worked for them. They configured the users account
properties in ADUC so that they were restricted to what computer they could
logon to and then they could not access domain resources from a non domain
computer assuming that the non domain computer did not have a name in the
list. That never occurred to me that it would work for network logon and I
tried it out and sure enough it worked giving some obscure message when I
tired to access a domain share. While it is not a foolproof security
solution it may help in smaller networks. Alas as you said none of this will
most likely stop a determined user from copying files anyhow from their
domain computer.

Steve


"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message
news:%23aLYveeyGHA.4336@xxxxxxxxxxxxxxxxxxxxxxx
Search on ms.com for the guidance papers on using
IPsec for "doman isolation"

You could apply techniques from them to all only domain
members to have network traffic with the fileshare server.

However, your users could/would just save copies to their
workstations and copy to their non-domain laptops/devices
from there (or email the docs out).

Your attempt to accomplish this by setting permissions to
administrators and domain computers did not work because
the access is not being done by the domain computers but by
the account logged into the domain comp, so the check is
against that user account, not the computer account.

<none@xxxxxxxxx> wrote in message
news:et4BpBeyGHA.1300@xxxxxxxxxxxxxxxxxxxxxxx
Single Windows Server 2003. All workstations are Windows XP SP2.

I'm trying to restrict access to the shared files on the Server to
computers
that are members of the Domain and so far it isn't working out too well.

Basically, we are allowing people to bring in laptop computers and
connect
to our network for Internet access and for access to certain printers but
do
not want to allow access to any shared files on the Server. We don't
want
any files copied to a laptop and leaving the premises. These computers
are
Workgroup computers; not Domain computers. I tried setting the
Permissions
for the shared files to only allow access by Administrators and Domain
Computers, but this cut off access by all computers even though the
computers I tested with were clearly members of the Domain Computers
group.

Any idea what I'm missing here? Do the Permissions/Security settings
need
to be some combination of Domain Computers and Authenticated Users in
order
to accomplish this?

Please help.

Thanks.

James




.



Relevant Pages

  • Re: List of servers in this workgroup is currently not available.
    ... Computer description appears before the computer name in the My Network ... Microsoft CSS Online Newsgroup Support ... <recently installed a D-Link print server with a reserved IP. ... <As soon as I uninstalled the print server and rebooted the computers, ...
    (microsoft.public.windows.server.sbs)
  • Re: Green Admin - Brute Force Attack - Pls Help
    ... Ipsec configuration is very similar [if ... specifics on how to use ipsec "filtering" policy to protect computers. ... is managing a network - particularly one in a hostile environment. ...
    (microsoft.public.security)
  • Re: Isolate systems
    ... You also may want to download the " Securing Windows 2000 Server Security ... to use ipsec "filtering" policies to secure domain controllers and other ... >> filtering policy on your computers which is a policy that uses rules with ...
    (microsoft.public.win2000.security)
  • Re: Isolate systems
    ... If you have access to the firewall, you might be able to configure what IP ... filtering policy on your computers which is a policy that uses rules with ... Ipsec policies are best when trying to configure for a subnet ... network layout you may be able to implement ...
    (microsoft.public.win2000.security)
  • Re: XP Firewall Quandry
    ... admin workstations if that would work and possibly even requiring an ipsec ... security association for those exceptions which would not allow computers ... Even the risk of having another network available can be ... enable the Windows Firewall in both domain and standard policy. ...
    (microsoft.public.windowsxp.security_admin)