Re: Granting domain accounts access to a workgroup resource



No you can not give "domain" accounts access by finding them and adding them
in the ACLs for a stand alone computer. Like I said you can create local
user accounts that have the same credentials as the domain users though that
is a lot of work for more then a few dozen users. Otherwise consider Roger's
suggestions. If need be as a last resort after making a risk management
decision you could leave the computer in the domain making sure that it is
properly hardened and monitored. If you do that however under no
circumstances logon to it locally or otherwise with any domain level
administrator account to manage [and configure user rights to enforce that
with the understanding that other administrators can modify those user
rights] it but instead use a local administrator account or regular domain
account that is in the local administrators group of that server only and
also make sure it has a unique password for the built in administrator
account and disable it so that is only available in Safe Mode. The risk
being that keyboard monitoring software could capture credentials and
malicious scripts could take advantage of such logons to escalate privileges
in the domain. Then also make sure that the firewall or ipsec policy only
allow it to access domain computers with the ports/protocols needed.

Steve


"Thomas Olsen" <thomas_olsen44@xxxxxxxxxxx> wrote in message
news:O4olUPz0GHA.4972@xxxxxxxxxxxxxxxxxxxxxxx
Thanks for your reply Steven

The computer is indeed a standalone machine and I am not able to grant
domain users any access to the server. I just wanted to get some feedback
if it should be possible to grant them access or not.

But I will stick to having everyone using FTP to access the data on the
server.

Thanks again.

/Thomas O

"Steven L Umbach" <n9rou@xxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:Ow3O79v0GHA.4796@xxxxxxxxxxxxxxxxxxxxxxx
You could only be able to add domain users if the computer was a member
of the domain or a trusted domain. I would double check that the computer
is indeed a stand alone computer if you can add domain users/groups. A
stand alone computer can only grant access to local users/groups that
could have the same credentials as domain users and allow access to share
assuming ipsec or such is not denying access.

Steve


"Thomas Olsen" <thomas_olsen44@xxxxxxxxxxx> wrote in message
news:%23WsUX0v0GHA.3476@xxxxxxxxxxxxxxxxxxxxxxx
Hi all

I am in the process of installing an FTP server in our organization
(Gene6 FTP server running on Windows Server 2003). The server is located
in DMZ. I would like internal domain users to be able to access it
through windows file sharing and external users to use FTP client.
So I thought for security reasons to not add this server to our internal
domain.

My problem then is that I am to able to add users from our domain to a
security group on the FTP server.

Is this not possible by design, or am I doing something wrong here?

Appreciate some feedback.

Thanks.

/Thomas







.



Relevant Pages

  • Re: FIRED IT ADMIN HAS LOCKED US OUT OF SBS
    ... you have risen to an Administrator this would be a given. ... server and run all LOB apps on these. ... If there are no encrypted files, just reset the DSRM account ...
    (microsoft.public.windows.server.sbs)
  • Re: FIRED IT ADMIN HAS LOCKED US OUT OF SBS
    ... Teneo> Interesting post and Im now gonna be a party pooper... ... connections) before cutting power to the server and to the Internet ... If there are no encrypted files, just reset the DSRM account ... and try old domain Administrator account's passwords. ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote desktop: cannot copy files why still not working
    ... I created a new user on the XP box, set as an administrator ... this new user account is local to the XP system, ... In my environment, when I do an RDP connection to a server, I first log ... member of the local administrators group on the server. ...
    (microsoft.public.windows.server.security)
  • Re: Remote desktop: cannot copy files why still not working
    ... this new user account is local to the XP system, and a member of the local administrator's group on that workstation. ... In my environment, when I do an RDP connection to a server, I first log on to the xp workstation using my regular, non-privileged domain account, run mstsc, and then logon to the server using a domain account that is a member of the local administrators group on the server. ... In addition, I frequently use runas to run privileged applications on the workstation using my "administrator" account, and have found that files cannot be copied between those applications and anything running under the credentials of my regular account - even though my administrator account actually does have full access to everything on the workstation - just not through my regular account's view of that workstation. ...
    (microsoft.public.windows.server.security)
  • Re: Shared Fax device not available anymore after reboot server!?!
    ... the error message one by one to the Newsgroup for accurate research. ... You can send fax by using Administrator account. ... after the reboot of the server no account is able to fax anaymore. ...
    (microsoft.public.windows.server.sbs)