Shared Folders in WorkGroup Network

R

RG

I have shared a folder on the server. However, the user
needs to be logged in to the server(ie username/password
logged in to the server must me the same as what was used
to log in to the workstation). Is there a way to allow
access to a folder on a network without logging in to the
server?

If not, what is the safest way to share these folders?

Thanks in advance,
 
D

Doug Sherman [MVP]

In Windows 2000, if you create a user account on the server which matches
the user name and password used to log onto the workstation, and you grant
Share/NTFS permissions to that user account; then the workstation user will
have access to the share regardless of whether you log onto the server with
a different user account. You should be able to do this even if no one is
logged onto the server - ie. if the server is booted to the Cntrl Alt Delete
screen.

You can create additional user accounts on the server by right clicking on
My Computer and selecting Manage. Expand Local Users and Groups, right
click on the Users folder, and select New User.

Doug Sherman
MCSE Win2k/NT4.0, MCSA, MCP+I, MVP
 
J

Jeff Qiu [MSFT]

Hi RG,

Thanks for posting!

When we share a folder in workgroup network, we may just set the share
permission and NTFS permission to everyone read in most cases.

This will enable anyone who can access this machine read the shared
information while not able to change anything in it.

This is basically a safe way as long as data corruption is the main concern.

If certain information is only intended to be view by a certain person, you
need to create a local user account for that person and let him know the
account/password.

Set the share permission to be only read by that user. Remove everyone from
the share permission. NTFS permission set to everyone read is OK.

When a user try to access this share, he(or she) will be prompted to enter
that user account/password. Thus, only pre-defined people can access it.

You may also want to grant full permission to that person if needed.

If anything else is unclear, please feel free to post back.

Hope this helps.

Best Regards,

Jeff Qiu
Microsoft Online Partner Support
MCSE 2k/2k3, MCSA 2k/2k3, MCDBA
Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.


--------------------
 
R

RG

Thanks for your help.

I realize this. However, I was looking for a way where you don't need to
have login on the server. In other words, where you are not going to get
prompted for user name /password.

I found, partially, the solution. If you enable guest account and give it
login privileges, you are not going to get prompted. The problem is you are
giving logon privileges and it's not quiet safe.


"Jeff Qiu [MSFT]" said:
Hi RG,

Thanks for posting!

When we share a folder in workgroup network, we may just set the share
permission and NTFS permission to everyone read in most cases.

This will enable anyone who can access this machine read the shared
information while not able to change anything in it.

This is basically a safe way as long as data corruption is the main
concern.

If certain information is only intended to be view by a certain person,
you
need to create a local user account for that person and let him know the
account/password.

Set the share permission to be only read by that user. Remove everyone
from
the share permission. NTFS permission set to everyone read is OK.

When a user try to access this share, he(or she) will be prompted to enter
that user account/password. Thus, only pre-defined people can access it.

You may also want to grant full permission to that person if needed.

If anything else is unclear, please feel free to post back.

Hope this helps.

Best Regards,

Jeff Qiu
Microsoft Online Partner Support
MCSE 2k/2k3, MCSA 2k/2k3, MCDBA
Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no
rights.


--------------------
From: "RG" <[email protected]>
Subject: Shared Folders in WorkGroup Network
Date: Tue, 7 Dec 2004 17:47:45 -0500
microsoft.public.win2000.networking

I have shared a folder on the server. However, the user
needs to be logged in to the server(ie username/password
logged in to the server must me the same as what was used
to log in to the workstation). Is there a way to allow
access to a folder on a network without logging in to the
server?

If not, what is the safest way to share these folders?

Thanks in advance,
 
J

Jeff Qiu [MSFT]

Hi RG,

Thank you for your update.

I do not know very clearly what the final goal is.

However, I would like to describe the way how file share is accessed.

The file share has a lock that is the share permission on it.

It is authenticated by the user account.

This provides a user level share control over the original Windows 9x
password level share control.

In work group mode, this authentication is done by checking the local user
account.

Thus, in the LAN, another user logs on to another machine who wants to
access this share must has the following condition:

Either his current logon account match the local account that get
permission to access this file share.
Or enter another credential that is able to access this file share.

Once we enable the guest account, this means everyone is granted the
permission to access this file share.

That's why you can access it without prmopting.

Please let me know more clearly the model you want to control your file
share and I will help you to correctly set it.

e.g. Server A get the file share, user A,B,C,D; user A,B can read access it
from client B; user C,D can read/write access it from client C.

Basically, the safest way is to establish a domain as workgroup networking
model is not used for high security purpose.

Best Regards,

Jeff Qiu
Microsoft Online Partner Support
MCSE 2k/2k3, MCSA 2k/2k3, MCDBA
Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.


--------------------
From: "RG" <[email protected]>
Subject: Re: Shared Folders in WorkGroup Network
Date: Tue, 7 Dec 2004 22:52:01 -0500
microsoft.public.win2000.networking

Thanks for your help.

I realize this. However, I was looking for a way where you don't need to
have login on the server. In other words, where you are not going to get
prompted for user name /password.

I found, partially, the solution. If you enable guest account and give it
login privileges, you are not going to get prompted. The problem is you are
giving logon privileges and it's not quiet safe.


"Jeff Qiu [MSFT]" said:
Hi RG,

Thanks for posting!

When we share a folder in workgroup network, we may just set the share
permission and NTFS permission to everyone read in most cases.

This will enable anyone who can access this machine read the shared
information while not able to change anything in it.

This is basically a safe way as long as data corruption is the main
concern.

If certain information is only intended to be view by a certain person,
you
need to create a local user account for that person and let him know the
account/password.

Set the share permission to be only read by that user. Remove everyone
from
the share permission. NTFS permission set to everyone read is OK.

When a user try to access this share, he(or she) will be prompted to enter
that user account/password. Thus, only pre-defined people can access it.

You may also want to grant full permission to that person if needed.

If anything else is unclear, please feel free to post back.

Hope this helps.

Best Regards,

Jeff Qiu
Microsoft Online Partner Support
MCSE 2k/2k3, MCSA 2k/2k3, MCDBA
Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no
rights.


--------------------
From: "RG" <[email protected]>
Subject: Shared Folders in WorkGroup Network
Date: Tue, 7 Dec 2004 17:47:45 -0500
microsoft.public.win2000.networking

I have shared a folder on the server. However, the user
needs to be logged in to the server(ie username/password
logged in to the server must me the same as what was used
to log in to the workstation). Is there a way to allow
access to a folder on a network without logging in to the
server?

If not, what is the safest way to share these folders?

Thanks in advance,
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top