Re: How to deny access to domain shares from a workgroup computer
- From: Meinolf Weber [MVP-DS] <meiweb(nospam)@gmx.de>
- Date: Tue, 28 Jul 2009 15:46:44 +0000 (UTC)
Hello swb,
A local user account on a workgroup computer not belonging to a domain can have access to a domain share when the share/NTFS permissions on the domain will allow this, for example both are set to Everyone Full control. Everyone group doesn't have the need for a domain SID, it's really everyone.
A local configured username on the workgroup computer will not sync a password with a domain user account even it has the same name, there is no sync running, don't know where you read/find this explanation, or maybe i understand you wrong.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
( I posted a version of the question the Small Business Server
newsgroup - no response - I hope that doesn't violate a posting rule )
Can anyone explain why a local account on a workgroup computer has
access to domain shares (sbs2008) if the local username and password
are synchronized with a domain username and password ?
The local workgroup account is allowed the same access as specified by
NTFS file permissions assigned to the domain account of the same
username/password.
I though the ACL on NTFS file shares on a Domain Controller required
the users access token to include a domain SID for the user.
This seems to be true on all Microsoft networks . . . I audit banks.
They give me a domain admin account for my visit. When I create a
matching account username/password on my notebook, I have access to
all shares on the Microsoft network, only using the domain account
they created for me for terminal service logins.
Is there a Security Option in to disable access to domain shares using
a synchronized local account on a workgroup computer.
Bigger Picture: What is all the Kerberos Trust path stuff about, if
access to shares only requires a synched username/password from any
workgroup ?
.
- Follow-Ups:
- Re: How to deny access to domain shares from a workgroup computer
- From: Paul Baker [MVP, Windows Desktop Experience]
- Re: How to deny access to domain shares from a workgroup computer
- From: swb
- Re: How to deny access to domain shares from a workgroup computer
- References:
- Prev by Date: How to deny access to domain shares from a workgroup computer
- Next by Date: Re: How to deny access to domain shares from a workgroup computer
- Previous by thread: How to deny access to domain shares from a workgroup computer
- Next by thread: Re: How to deny access to domain shares from a workgroup computer
- Index(es):
Relevant Pages
|