Combine share and NTFS permissions on win-srv and predict the result

applied · 50 min · Objective 3.3

Task

On win-srv, share a folder with deliberately different share and NTFS permissions, predict each user's effective access over the network, and then test it from a client. Finish by finding local accounts nobody has used, the first step of an access review.

Steps

  1. On win-srv, create local users dana, elliot and fay, and groups Finance-RW (dana) and Finance-RO (elliot).
  2. Create the folder C:/Finance with New-Item -ItemType Directory and share it with share permissions giving Everyone Read only. Set NTFS permissions: Finance-RW Modify, Finance-RO Read. Save Get-SmbShareAccess Finance and icacls C:/Finance to lab/ntfs/permissions.txt.
  3. Write lab/ntfs/predict.csv with header user,network_read,network_write before testing.
  4. From the client, connect as each user and try to read and write a file. Record results in lab/ntfs/results.csv with the same header.
  5. Change the share permission to Everyone Full Control, retest dana's write, and record the result in lab/ntfs/after-change.txt as allowed or denied.
  6. List local accounts with their last logon time using Get-LocalUser | Select Name,Enabled,LastLogon and save it to lab/ntfs/review.txt.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -Eic 'Finance-RW|Finance-RO' lab/ntfs/permissions.txt
diff lab/ntfs/predict.csv lab/ntfs/results.csv && echo predictions matched
awk -F, '$1=="dana" {print "dana write over the share: "$3}' lab/ntfs/results.csv
grep -Eic 'success|allowed|written' lab/ntfs/after-change.txt
grep -Ec 'dana|elliot|fay' lab/ntfs/review.txt

Your predictions match the results. With the share at Read, dana could not write over the network even with NTFS Modify, because the more restrictive of the two applies; after the share was opened up, she could. fay, in neither group, has no access either way.

Notes

The common practice is to set share permissions broadly and manage access with NTFS permissions alone, so there is one place to look. This lab's first configuration is the troubleshooting case: a user with the right NTFS rights who still cannot write.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.