70-270: MCSE Guide to Microsoft Windows XP Professional (MCSE/MCSA Guides)

You use shared folders to provide network users with access to file resources. When a folder is shared, users can connect to the folder over the network and access the files it contains. However, to access the files, users must have permissions to access the shared folders.


After this lesson, you will be able to

Estimated lesson time: 30 minutes


Shared Folder Permissions

A shared folder can contain applications, data, or a user's personal data, called a home folder. Each type of data requires different shared folder permissions.

The following are characteristics of shared folder permissions:

A shared folder appears in Windows Explorer as an icon of a hand, shown in Figure 9.1, holding the shared folder.

Figure 9.1 Shared folders in Windows Explorer

To control how users gain access to a shared folder, you assign shared folder permissions. Table 9.1 explains what each of the shared folder permissions allows a user to do, presented from most restrictive to least restrictive.

Table 9.1 Shared Folder Permissions

Shared folder permission Allows the user to

Read

Display folder names, filenames, file data, and attributes; run program files; and change folders within the shared folder

Change

Create folders, add files to folders, change data in files, append data to files, change file attributes, delete folders and files; also allows the user to perform actions permitted by the Read permission

Full Control

Change file permissions, take ownership of files, and perform all tasks permitted by the Change permission

You can allow or deny shared folder permissions. Generally, it is best to allow permissions and to assign permissions to a group rather than to individual users. Deny permissions only when it is necessary to override permissions that are otherwise applied, for example, when it is necessary to deny permission to a specific user who belongs to a group to which you have given the permission. If you deny a shared folder permission to a user, the user won't have that permission. For example, to deny all access to a shared folder, deny the Full Control permission.

How Shared Folder Permissions Are Applied

Applying shared permissions to user accounts and groups affects access to a shared folder. Denying permission takes precedence over the permissions that you allow. The following list describes the effects of applying permissions:

When you copy a shared folder, the original folder is still shared, but the copy is not. When you rename or move a shared folder, it is no longer shared.

Guidelines for Shared Folder Permissions

The following list provides some general guidelines for managing your shared folders and assigning shared folder permissions:

Table 9.2 describes share and folder naming conventions for different client computer operating systems.

Table 9.2 Client Computer Operating Systems and Share Name Length

Operating system Share name length

Windows XP and Microsoft Windows 2000

80 characters

Microsoft Windows NT, Microsoft Windows 98, and Microsoft Windows 95

12 characters

MS-DOS, Microsoft Windows 3.x, and Microsoft Windows for Workgroups

8.3 characters

Microsoft Windows XP Professional provides 8.3-character equivalent names, but the resulting names might not be intuitive to users. For example, a Windows XP Professional folder named Accountants Database would appear as Account~1 on client computers running MS-DOS, Windows 3.x, and Windows for Workgroups.

Practice: Applied Permissions

In the following practice, User101 has been assigned permissions to access resources as an individual and as a member of a group, as shown in Figure 9.2.

Figure 9.2 Applied permissions

Determine which effective permissions are assigned for User101 and User2.

  1. User101 is a member of Group1, Group2, and Group3. Group1 has Read permission. Group2 has Full Control permission for FolderA, and Group3 has change permissions assigned for FolderA. What are User101's effective permissions for FolderA?
  2. User102 has been granted the Full Control shared folder permission for FolderB as an individual user. User102 is a member of the Managers group, which has been granted Change permission for FolderB, and a member of the Sales group, which has been denied all access to FolderB. What are User102's effective permissions for FolderB?

Lesson Review

The following questions will help you determine whether you have learned enough to move on to the next lesson. If you have difficulty answering these questions, review the material in this lesson before beginning the next lesson. The answers are in Appendix A, "Questions and Answers."

  1. Because you use NTFS permissions to specify which users and groups can access files and folders and what these permissions allow users to do with the contents of the file or folder, why do you need to share a folder or use shared folder permissions?
  2. Which of the following permissions are shared folder permissions? (Choose all answers that are correct.)
    1. Read
    2. Write
    3. Modify
    4. Full Control

  3. ______________________ (Denied /Allowed) permissions take precedence over ____________ (denied /allowed) permissions on a shared folder.
  4. When you copy a shared folder, the original folder is ___________________ (no longer shared /still shared) and the copy is ______________________ (not shared /shared).
  5. When you move a shared folder, the folder is ______________________ (no longer shared /still shared).
  6. When you rename a shared folder, the folder is ______________________ (no longer shared /still shared).

Lesson Summary

Категории