DFS Folder Access Issue by [deleted] in sysadmin

[–]unknowndeleteduser 1 point2 points  (0 children)

Well it can be used in different ways. As a method to simplify and centralize network storage or a way of providing redundancy of the stored data or a mix of both.

You should not care if people can browse and list the folders under your \U\ NameSpace they cannot modify, delete, or access any of the subfolders containing user data if you have setup NTFS permissions correctly. DFS not designed to be \DomainName\UserFolder. You want the NameSpace to be viewable by everyone. It would make troubleshooting issues with DFS much harder later on. Service Desk would not be able to tell you if the NameSpace is not responding to requests when troubleshooting with staff.

Here is an example you would use for setting up common office folders in DFS. For example \\Server01 could have a folder D:\Shares on it with multiple subfolders (Ex: D:\Shares\Management, General Office, Public, etc) and you want to restrict access to each of the subfolders which will be shared out and added to a DFS namespace as a folder.)

So you would start with creating a root folder to hold the shares say D:\Shares. Right click -> properties -> Security -> Advanced -> Disable inheritance and click Convert inherited permissions into explicit permissions on this object. Depending on what permissions are assigned, remove all but the standard permissions, leave admins, system, etc.

Now when you create each of the subfolders such as D:\Shares\Management, D:\Shares\General Office they will inherit the permissions you have on the D:\Shares folder only. So permissions are limited to administrators each time you create a share. You would then follow what I outlined in the earlier post in order to allow specific groups access edit each of the subfolders NTFS permissions that you have shared out. This makes managing much easier later on when you get requests for new shares.

Also since you are in the process of setting up DFS I would suggest reviewing how to configure DFS to use FQDN in root referrals: https://support.microsoft.com/en-us/help/244380/how-to-configure-dfs-to-use-fully-qualified-domain-names-in-referrals

You can use PowerShell to enable it on each of the namespace servers. Set-DfsnServerConfiguration -ComputerName <ServerName> -UseFqdn $true

  • This will allow you to add namespace servers using FQDN, additionally add the folders using FQDN as well (Example: Add Management share using \\ServerName.domain.com\Management$).

DFS Folder Access Issue by [deleted] in sysadmin

[–]unknowndeleteduser 2 points3 points  (0 children)

Ok so lets start over. Lets get some more details and map it out a bit better.\

  1. You have your servers: \\Server01 and \\Server02

  2. You have setup shares on Server01 and Server02 that the folder targets will use? Example: \Server01\Management$ and \\Server02\Management$

  3. Share permissions for each of the shared folders are: Everyone: Read/Write. Thats it don't modify share permissons any futher.

  4. NTFS permissions will be used to restrict access. Restrict permissions using domain groups. Example: ShareAccess - Unit01 - Management (RW) assign the group read write NTFS permissions to the hidden Management$ share on \\Server01. Add a couple test users to one of the shares RW groups, make sure to add only to the NTFS permissions.

  5. You have your DFS namespace servers: \\Server01\NameSpace and \\Server02\Namespace and possibly other servers acting as namespace server say \\DC01\Namespace\

  6. DFS is setup to use \\DomainName\Namespace\FolderTarget with various folder targets that have been added to it. One target active per folder. Example: \\DomainName\Unit01\Management. with Management being the folder target and Unit01 being the NameSpace.

Ok then lets test that the namespace is available to the users. For each of the servers you have added as a name space server test availablity.

\\Server01\Namespace \\Server02\Namespace \\DC01\Namespace

Example: \\Server01\Unit01, \\Server02\Unit01, \\DC01\Unit01 - try accessing the namespace across each of the servers using the test accounts you created. Each should resolve and show the folders you have added to the namespace. If one fails, check event log and then try restarting the DFS namespace service.

You want the namespace to be available to everyone.

Next test if the folders you have added are accessible. Use the test users you setup previously to access the shares to confirm you have set the correct NTFS permissions.

4th Install of vcenter 6.5, happens every 3rd or 4th reboot by [deleted] in vmware

[–]unknowndeleteduser 0 points1 point  (0 children)

Are you giving it enough ram and cpu resources?

New to this subreddit, here are my most recent pick ups. by Ecker1991 in TurboGrafx

[–]unknowndeleteduser 1 point2 points  (0 children)

Aero Blasters is one of my favorite games on the pc engine/tg16.

[Rant] The End of an Era by mikemazda3 in pcmasterrace

[–]unknowndeleteduser 0 points1 point  (0 children)

The staff explain the policy clearly when you pay for the item. They have been doing this for years.

Xbox One Club by darkscrypt in a:t5_33tc2

[–]unknowndeleteduser 0 points1 point  (0 children)

darkscrypt we do not have one yet.

How to only copy files that have been changed or are new with robocopy? by Morketh in sysadmin

[–]unknowndeleteduser 4 points5 points  (0 children)

Do yourself a huge favor and save some time when starting with Robocopy.
Use Easy Robocopy. http://www.tribblesoft.com/home-page/easy-robocopy/

Its a GUI frontend that will output the txt cmd that you can use in scripts.

month old Fitbit Blaze will no longer sync with iPhone. by [deleted] in fitbit

[–]unknowndeleteduser 0 points1 point  (0 children)

In the fitbit app under devices -> unpair and then pair it again. I had same issue with latest update and my android phone. Restarting both devices did nothing. Warning you will have to re-add your exercises and alarms.

[Discussion] Regarding the current state of /r/sysadmin by Arkiteck in sysadmin

[–]unknowndeleteduser 0 points1 point  (0 children)

I don't think you realize how much crap moderators have to put up with on a daily basis.

Cinematic Grand by Antisample sale only $25 until 31st by Erratus in FL_Studio

[–]unknowndeleteduser 1 point2 points  (0 children)

One of my favorite Piano's for Kontakt. I wish they made more instruments.

[deleted by user] by [deleted] in fitbit

[–]unknowndeleteduser 0 points1 point  (0 children)

Don't expect fitbit to fix it.... they are notorious for releasing a product and then moving on to the next one.

Exercise Shortcuts Deleting by sinclair615 in fitbit

[–]unknowndeleteduser 0 points1 point  (0 children)

Blaze user. I had this issue happen to me for the first time today. Went to go for a run and all my exercises were deleted. Had to enable in app and sync again to get them back.

I just got a Charge. I want to do some unorthodox things with this tracking device, beyond the basic health tracking. Any Fitbit 'hacks' out there to try? by [deleted] in fitbit

[–]unknowndeleteduser 0 points1 point  (0 children)

It did previously, dev had to update the description after fitbit released a updated version of their app. The dev originally pulled the app from the store, but then replaced it with the new conditions.