How to prevent users on unauthorized machines from w2k3 files

How to prevent users on unauthorized machines from w2k3 files

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
How to prevent users on unauthorized machines from w2k3 files Scott 11-27-2007
Posted by =?Utf-8?B?U2NvdHQ=?= on November 27, 2007, 4:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I want to prevent a user from accessing the fileshare if they come from an
unauthorized machine.
As of now, if Joe User brings in his personal laptop and plugs it into the
network, and tries to access a Windows 2003 file share, it prompts them for
username/password. If they enter their AD uname/pw, they can gain access.

How can I prevent authorized users on unauthorized machines from gaining
access to W2K3 file shares?

Posted by Roger Abell [MVP] on November 27, 2007, 10:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
With what is included in Windows you need to decompose your
problem. It is not "how to prevent authorized user on unauthorized
machine" but "how to prevent any account on unauthorized machine".
That is, you can use such as IPsec to control what machines can
access the machine with the shares, which combined with NTFS
and share level permissions for user access control does allow
you to make sure that only allowed account may access the shares
from that machine when they are on allowed machines.

However, you probably need to take a step back and ask what
it is that you actually achieve. If they can bring a machine in
and out, then they easily can copy onto a usb device or use an
authorized machine to map a share from their unauthorized
machine and then copy to it via their login at an authorized
machine.

Roger

>I want to prevent a user from accessing the fileshare if they come from an
> unauthorized machine.
> As of now, if Joe User brings in his personal laptop and plugs it into the
> network, and tries to access a Windows 2003 file share, it prompts them
> for
> username/password. If they enter their AD uname/pw, they can gain access.
>
> How can I prevent authorized users on unauthorized machines from gaining
> access to W2K3 file shares?



Similar ThreadsPosted
How to prevent users from deleting Word/Excel files in a Share? May 14, 2008, 9:45 pm
Prevent Unauthorized PCs to connect on the LAN August 7, 2007, 1:33 pm
Prevent files from being copied August 25, 2005, 9:01 am
How to Prevent Users from Moving Folders April 25, 2007, 7:32 am
Group policy to prevent users to safe password February 20, 2007, 5:48 am
Stop Users Deleting and Moving Files June 16, 2006, 10:21 am
How to give multiple users access to encrypted files. June 26, 2006, 6:22 pm
Users cannot modifie files with disable option delete subfolders f December 12, 2007, 11:45 am
Unauthorized use of Server 2003 February 4, 2006, 8:21 am
unauthorized remote access February 16, 2006, 3:17 am

The site map in XML format XML site map

Contact Us | Privacy Policy