How to deny access to domain shares from a workgroup computer




( I posted a version of the question the Small Business Server newsgroup -
no response - I hope that doesn't violate a posting rule )

Can anyone explain why a local account on a workgroup computer has access to
domain shares (sbs2008) if the local username and password are synchronized
with a domain username and password ?

The local workgroup account is allowed the same access as specified by NTFS
file permissions assigned to the domain account of the same
username/password.

I though the ACL on NTFS file shares on a Domain Controller required the
users access token to include a domain SID for the user.

This seems to be true on all Microsoft networks . . . I audit banks. They
give me a domain admin account for my visit. When I create a matching
account username/password on my notebook, I have access to all shares on the
Microsoft network, only using the domain account they created for me for
terminal service logins.

Is there a Security Option in to disable access to domain shares using a
synchronized local account on a workgroup computer.

Bigger Picture: What is all the Kerberos Trust path stuff about, if access
to shares only requires a synched username/password from any workgroup ?



.



Relevant Pages

  • Re: How to deny access to domain shares from a workgroup computer
    ... computer with the same username and password as a domain account. ... If the account on the domain is a domain admin, ... I also have access to the C$ D$ admin shares with the workgroup account. ... A local user account on a workgroup computer not belonging to a domain can ...
    (microsoft.public.windows.server.security)
  • Re: How to deny access to domain shares from a workgroup computer
    ... account, I am granted the same access as that domain account. ... A local user account on a workgroup computer not belonging to a domain can ... access to domain shares if the local username and password ... I though the ACL on NTFS file shares on a Domain Controller required ...
    (microsoft.public.windows.server.security)
  • For Discussion......amtd
    ... Shares Short: 12.44M ... AMERITRADE for self-directed retail investors; ... and other account holders to spammers, who then sent the account holders ...
    (misc.invest.stocks)
  • Re: I cant connect to my server
    ... A likely reason for the username/password failing is account corruption. ... As a minimum, email scanning in the antivirus must be turned off, ... I have included the text of the error message ... ...
    (microsoft.public.windows.vista.mail)
  • Re: Accessing SBS 2003 Shares with XP Home
    ... can see in server in network neighborhood. ... I have tried user password and admin password. ... access shares very easily. ... of the Admin account that was assigned to that share. ...
    (microsoft.public.windows.server.sbs)

Quantcast