How to Cheat at Installing, Configuring and Troubleshooting

Windows 2000 File Systems

This special Syngress e-book is designed to provide quick, step-by-step help to anybody trying to wrestle with Win 2K

File System Management

TOPIC 1: EFS AND ENCRYPTING DATA… 4

FILE ENCRYPTION… 6 DECRYPTION OF FILES… 6 STORING ENCRYPTED FILES ON REMOTE SERVERS… 6 ACCESSING ENCRYPTED DATA… 6 MOVING AND RENAMING ENCRYPTED DATA… 6 DECRYPTING DATA… 6 THE RECOVERY AGENT… 7

TOPIC 2: NTFS AND MANAGING DISK QUOTAS… 8

TOPIC 3: USING DISK DEFRAGMENTER… 15

ANALYZING A DRIVE… 17 VIEWING REPORTS… 17

TOPIC 4: DEFRAGMENTING NTFS FILE SYSTEM PARTITIONS… 19

TOPIC 5: FILE AND FOLDER PERMISSIONS… 20

NTFS FOLDER PERMISSIONS… 20 NTFS FILE PERMISSIONS… 20 HOW WINDOWS 2000 APPLIES NTFS PERMISSIONS… 21 Access Control Lists… 21 Combining NTFS Permissions… 21 Permissions Are Cumulative… 21 File Permissions Override Folder Permissions… 21 Deny Overrides All Other Permissions… 21 Permission Inheritance… 22 ASSIGNING NTFS PERMISSIONS… 22 PLANNING NTFS PERMISSIONS… 22 MANAGING NTFS PERMISSIONS… 22 SPECIAL ACCESS PERMISSIONS… 25 Take Ownership… 25

Copyright © 2003 by Syngress Publishing. All Rights Reserved.

How to Cheat…

Change Permissions…26 Other Special Permissions… 26 USING SPECIAL ACCESS PERMISSIONS… 27 Setting the Special Access Permissions… 27 Taking Ownership of Files and Folders… 29 CHANGING NTFS PERMISSIONS… 30

TOPIC 6: COPYING AND MOVING FILES AND FOLDERS… 31

COPYING FILES… 31 MOVING FILES… 31 SHARING RESOURCES… 32 SECURING NETWORK RESOURCES… 33 SHARED FOLDER PERMISSIONS… 33 CREATING SHARED FOLDERS… 34 DEVELOPING A SHARED FOLDER STRATEGY… 34 Shared Applications… 34 Shared Data… 35 SHARING FOLDERS… 35 Administrative Shares…35 Creating a Shared Folder… 36 Assigning Permissions to a Shared Folder… 38 Managing Shared Folders… 39 Connecting to a Shared Folder… 41

TOPIC 7: NTFS PERMISSIONS AND SHARED FOLDERS… 44

TOPIC 8: ENCRYPT AND DECRYPT FILES… 46

DECRYPTING A FILE… 46

TOPIC 9: DATA AND DIRECTORY COMPRESSION… 47

COMPRESSING FILES AND FOLDERS… 47 Disk Space Requirements… 51 Compression State… 51 Compression Rules… 52 Copying and Moving Compressed Files and Folders… 52 Copying a File within an NTFS Volume… 52 Moving a File or Folder within an NTFS Volume… 52 Copying or Moving a File or Folder between NTFS Volumes… 53 Moving or Copying a File or Folder from an NTFS Volume to a FAT Volume or to a Floppy Disk… 54

TOPIC 10: WHAT CAN GO WRONG, WILL…… 56

TROUBLESHOOTING ACCESS PROBLEMS… 56 Solving Permission Problems… 56 Typical Permission-Related Access Problems… 56 Solving Permission-Related Access Problems… 56 AVOIDING PERMISSION-RELATED ACCESS PROBLEMS… 56

Copyright © 2003, Syngress Publishing. All Rights Reserved.

TOPIC 11: HANDY FILE & DIRECTORY TOOLS AND LINKS… 58

CIPHER UTILITY… 58 RECOVERY OPERATIONS… 58 TWEAKUI UTILITY… 58

TOPIC 1: EFS and Encrypting Data

Using data encryption is similar to using a secret code to record your most personal thoughts in a journal. You want to ensure that no one else will be able to read your journal, but you do not want to have to lock it up or hide it, so you invent your own secret code. Only you and one of your closest friends know how to unscramble the code to read what was written. Sometimes directory and share permissions are just not enough. This is where EFS comes in. EFS is the acronym for the Windows 2000 Encrypting File System. EFS allows users to encrypt data in selected NTFS files and folders so that it can be stored securely on the computer. EFS is quite simple to use, and is invisible to the user. It is also very difficult to attack because it is incorporated with the file system. Once a user decides what data to encrypt, a private key is created so that only the user will be able to unlock the code. Although encrypted files cannot be viewed by anyone other than the user who encrypted them, they can be deleted by anyone, just as a diary can have pages ripped out. EFS can be used only with data accessed by a single user and stored on that user’s local computer or on the server. It does not work with shared files and folders, nor can the user who encrypted the data give others encrypted access to the data. Using EFS, users can encrypt, decrypt, access, move, copy, and rename their files. EFS is set up by default so that users can automatically begin encrypting their files at any time. It automatically creates an encryption key pair for users when they encrypt their first file or folder as long as they do not already have one. Encryption is managed through Windows Explorer or the cipher command line utility.

FFoorr IITT PPrrooffeessssiioonnaallss OOnnllyy

An alternative way to configure data encryption is to use the cipher command from a command line. To see the command line options for the cipher command, type “cipher /?” at a command line as shown in the following figure.

These are the cipher /? command line options.

To encrypt a file or folder, simply right-click the file or folder and choose Properties from the pop-up menu. Click the Advanced button and then add a check mark to the “Encrypt contents to secure data” check box (see the following figure).

Use the Advanced Attributes dialog box to select file and folder encryption.

If you are encrypting a folder, a Confirm Attribute Changes dialog box will pop up, asking you whether you would like to encrypt only the folder, or the files and subfolders within the folder as well. If you choose the latter option, any files and subfolders that you add to the encrypted folder will also be encrypted (see below). Keep in mind that compression cannot be combined with encryption. They are mutually exclusive.

The Confirm Attribute Changes dialog box confirms encryption attributes.

If you choose to apply the changes to the files and subfolders within the folder, then an Applying Attributes box, similar to the compression status indicator, will appear. If you decide that you no longer

want to apply the changes, you can click Cancel, but the changes will still be applied to those files and folders whose attributes have already been changed. This makes it difficult to determine what was actually encrypted and what was not. That is all the user sees of the encryption process, but there is a lot more going on in the background.

File Encryption

Once you elect to encrypt a file, a unique file encryption key will be created that will be used later to decrypt the data as required. The file encryption key is encrypted also, to provide maximum security. Both the user’s public key and the public key of the recovery agent encrypt both the file and the encryption key. The user’s public key corresponds to the user’s EFS certificate, so that this user is the only one who can view the files. Folders do not get encrypted; only the files within the folders are encrypted, because the encryption key encrypts only files. Neither system files nor compressed files can be encrypted.

Decryption of Files

Before a file can be decrypted, the file encryption key must be decrypted. This can take place only when the user’s private key matches the public key. The only person who can decrypt the file is the user who encrypted the file. The only exception to this rule is when the recovery agent is called upon to decrypt a file that can no longer be encrypted. This can be done by using the emergency recovery agent’s private key.

Storing Encrypted Files on Remote Servers

Windows 2000 supports the storage of encrypted files on remote servers, but encrypted files are still limited to single users for decryption. Because encrypted data is not usually encrypted when it is being transported over the network, it is not as secure as it would be if it were stored on a local computer. A user can encrypt files that reside on a remote server only if the administrator first designates the remote server as “trusted for delegation.” This is not set up by default, so you must remember to configure this if you need to have data encrypted while it is being transported. After this is set, all users can encrypt their files that reside on that server.

Accessing Encrypted Data

Accessing encrypted data looks exactly the same to the end user as accessing regular data. EFS works transparently in the background, but only when the user who encrypted the file tries to access it. A user who did not encrypt a file or folder but who tries to access encrypted data will receive an “Access Denied” message, because that user does not have the correct private key that corresponds to the file’s or folder’s public key.

Moving and Renaming Encrypted Data

When a user renames an encrypted file, the file retains its encryption state. For example, if you rename a file that is encrypted, it will still be encrypted after the name is changed. Similarly, when a user moves a file to another folder, the file retains its encryption state whether or not the destination folder is encrypted.

Decrypting Data

Decrypting data is simple. All the user has to do is remove the check mark from the encryption check box in the file’s properties. Once a file is decrypted, it will stay unencrypted until a user encrypts it again.

The Recovery Agent

Private keys are kept in a protective key store. If users lose their file encryption certificates and private keys, they can be recovered by using the recovery agent. The recovery agent, which can decrypt their files, is part of the recovery policy that is implemented when a user receives the first file encryption certificate. When the recovery agent receives the data recovery certificate, it should export it, store it in a safe place, and then delete the data recovery certificate from the system hard disk. This way only the person who has physical access to the data recovery certificate can recover the data. If a user loses a private key and you need to carry out data recovery, the data recovery certificate can be obtained by the recovery agent from the storage location and imported back into the system. Once the data recovery certificate is imported back into the system, the recovery agent can then use the data recovery certificate to perform the data recovery from the user’s encrypted files. When you complete the data recovery, the data recovery certificate should be deleted immediately from the system for security reasons, so that there is no chance that someone can access it after you are finished using it. There is no reason to export the data recovery certificate back to the safe storage area, because it is still stored there and can be imported over and over again. If you attempt to use the encrypted file system (EFS) on a Windows NT NTFS partition, Windows 2000 automatically upgrades the partition to Windows 2000 NTFS format so that you can encrypt the data.

TOPIC 2: NTFS and Managing Disk Quotas

Disk quotas are similar to credit card limits. When you have a credit card that has a limit of 3,000. However, if you have reached your credit limit and you want to charge anything else to your credit card, you need to pay off some of the balance first. Disk quotas are used to manage the growth and size of file storage for each user or groups of users. They allow you to determine how much disk space each user or groups of users receive (credit limits) and ensure that they do not go over that limit or quota. Like compression, disk quotas can only be used with the NT file system (NTFS). Disk quotas are managed through the Windows 2000 Disk Quota Manager (the credit card company). Through this utility, you can set disk quotas (credit card limits), send messages to users when they are approaching their quota, and disable further saving of data (any more charges to the card) until the users get back within their allotted quota (until some of the credit card bill is paid off). Windows 2000 Disk Quota Manager tracks disk usage for each user, no matter what folders their files are in or where the folders are stored on the network. Quotas are managed on each individual volume, not in combined volumes. Windows 2000 calculates disk usage based on the files and folders that each user owns. Windows 2000 “charges” the disk space against the user’s quota limit when the user creates or takes ownership of a file or folder. When Windows 2000 calculates hard disk space, it ignores compression, because files of different types can be compressed by different percentages, making it hard to predict the real size of the file; therefore, users are charged for each uncompressed byte. You can use disk quotas to set the disk quota limits for each individual user or for all users, determining how much disk space they can use and whether they can log an event. Once that is completed, you can set a disk quota warning so that users will receive a message informing them when they are approaching their limit. You can also set the consequences, determining what will happen when users reach their disk quota limit. For example, when users approach their quota limit, you can deny them any further disk space or you can let them continue using the resources. Once you set up disk quotas, Windows 2000 will begin collecting disk usage information for all users who own files and folders on each volume. This allows anyone in the administration group to monitor the disk quota levels on a per volume basis. To enable disk quotas, right-click the volume for which you would like to set disk quotas, select Properties, and then choose the Quota tab from the Disk Properties box. From here, several options can be configured, including the primary option, which enables quota management for this volume (see the following figure).

Use the Quota tab to enable and disable disk quotas.

Select the first check box, “Enable quota management,” so that you can start using quota management. Once you select the check box, you can access the other options that were previously grayed out. The second check box is “Deny disk space to users exceeding quota limit.” Select this check box if you want users to be denied any further use of space once they exceed their quota limit. This is selected by default after you choose to enable quota management, so if you do not want to deny users disk space and would rather simply keep them informed when they are using more than they should, then you should uncheck this box. When this option is selected, users will receive an “Out of disk space” warning message when they save files, informing them that they have exceeded their quota and that they will have to decrease the number of their files and folders in order to continue. The next option configures the default quota limits for new users on the volume. These settings will define the default settings for any new users who access that volume. You can either choose the “Do not limit disk usage” radio button or you can set the option to limit space. When you set the Limit Disk Space option, you can specify both disk space and warning level limits. The default is set not to limit disk space usage. The next section sets the logging options for the volume. There are two check boxes; one is used to choose whether to log an event when a user exceeds a quota limit, and the second is used to choose whether to log an event when a user exceeds the warning level. You can choose one, both, or neither of these check boxes, depending on how much information you want to have recorded in your event log. It is a good idea to log an event when users’ quota limits have been exceeded so that you can ensure that they

get below their quota limit again as soon as possible. When you set the quota logging options, the information will be logged in the system log within the event viewer (see the following figure).

Disk quota events are logged in the system log.

A quick way to determine the status of the disk quotas is to look at the traffic light in the top left-hand corner of the Quota tab. When the traffic light is green, the quota system is active and working; when the traffic light is yellow, it is rebuilding disk quota information; and when the traffic light is red, the quota system has been disabled. There is also a Quota Entries button on the Quota dialog box. Click this button to view all the quota entries for the disk that you have selected. You can use this area to set quota limits for specific users (see the next figure. If you want to configure quotas for all users, you can do this in the Local Disk Properties dialog box.

This is the Quota Management console.

The Quota Entries dialog box monitors each user’s disk usage on the volume. It shows who has copied, saved, or taken ownership of files and folders on the drive. It can be used to determine how much disk space each user is using, as well as each user’s quota warning level and disk quota limit. A yellow triangle represents the users who are over their quota warning level, and a red circle signifies users who have exceeded their quota limit. You can change the view of the Quota Entries dialog box so that you can view the items in the dialog box arranged by any of these parameters:

Folder User Name Logon Name Status Amount Used Quota Limit Warning Level Percent Used

To change the method by which entries are displayed, choose the View menu, then the Arrange Items option, and then the view that you would like to use (see the following figure).

You can use the Quota Entries text box to change the way quota entries are arranged.

To add a quota entry, select the Quota menu and then choose “New quota entry” from the drop-down box. A box then comes up, asking you from where you would like to select the user (see the figure below). You can click the name and click Add, or you can double-click the name. Alternatively, you can type the name in the Name box and click Add. From there, you can click the Check Names button to ensure that the names you typed can be found and that the path to those names is set up. If the name cannot be found in any path, an Invalid Name text box pops up, prompting you to correct the name and search again or to remove the name from the name selections for the new quota entry.

Choose the users to whom to apply a new quota entry.

Then an Add New Quota Entry dialog box pops up, asking you to set the quota limit for the selected users. You can then choose whether to limit disk usage and what the limitations will be for the users. You can choose whether to limit disk space for the selected users, just as you did when you set quotas for an entire volume. To limit the disk space for the users, simply click the Limit Disk Space To button and set the limit amount. Then set the warning level limit if you would like users to receive a warning before they reach their disk limit. You may need to delete the quota entries for a user who leaves the company. Before you do so, the files and folders that the user owned must no longer be owned by that user. Those files and folders must be moved onto another volume without having disk quotas set up for them, or else another user must take ownership of them. If this is not done, you will be unable to delete the quota entries for the user who left. To delete a quota entry for a user, simply choose the Quota menu and then click Delete Quota Entry from the drop-down box (see below). A dialog box will pop up, asking you if you are sure that you would like to delete that quota entry.

This is how a quota entry is deleted.

TOPIC 3: Using Disk Defragmenter

Disk file systems can become fragmented with heavy use. Fragmentation occurs when files are split into noncontiguous areas on the disk, because Windows 2000 saves files in the first available space on your hard drive, not necessarily in a place that can fit your entire file into one section. Fragmentation slows disk performance and can result in wear and tear on the disk, because the disk heads must jump to multiple areas of the disk trying to read or write data belonging to a single file. You can use the Windows 2000 disk defragmenter to defragment the files on your hard disks periodically (see the following figure). This consolidates all the pieces of your files into a single space on the hard drive so that your computer can access the files more quickly and efficiently. To use the disk defragmenter, you must be a member of the administrator group. Without administrator group privileges, you will be unable to defragment the drive. The Windows 2000 disk defragmenter can defragment FAT, FAT32 and NTFS volumes.

This is the Windows 2000 Disk Defragmenter.

To use the disk defragmenter, you can right-click a drive in My Computer or Windows Explorer, choose Properties, and then the Tools tab. From there, you can choose to defragment the volume. Alternatively, you can go to the disk defragmenter by clicking the Start menu, choosing Programs, then Accessories, then System Tools, and finally Disk Defragmenter. Both ways display the disk defragmenter window, showing the disk status for all the volumes. There are two options in the Windows 2000 Disk Defragmenter. The first is the Analyze option, which analyzes the disk to see how fragmented it is. After it completes the analysis, it displays a band showing how fragmented the drive is (see the next figure). From there, you can determine whether you want to use the Defragment option. The Defragment button

defragments the disk and, once defragmentation is complete, displays a band representing the defragmented volume. The Disk Defragmenter window is divided into three areas. The top layer displays all the volumes that you can defragment, including information on the file system in use and how the space is distributed. This includes the capacity of the volume and the amount of free space available in MB as well as a percentage value. It also informs you of the status of the session. The second and third layers are graphical representations of the volume and its various fragmentation states. The first horizontal bar graph is called the analysis display. It displays the fragmented volume as it is initially analyzed. You should use the analysis display only for a general idea of how fragmented the volume is. You should use the analysis report for precise, numerical data. The second horizontal bar graph displays the drive as it is being defragmented. The bars are displayed this way so that you can compare them to see the improvement in fragmentation after you run the disk defragmenter. You can actually view a graphical representation of the defragmenting as it is taking place (see below).

This is the graphical representation of the volume analysis and defragmentation in process.

The volume being defragmented has different colors representing the various fragmenting conditions. There is a legend at the bottom of the disk defragmenter indicating the various color representations:

Red represents fragmented files Blue represents contiguous files Green represents system files White represents free space

It is a good idea to analyze the volume before you defragment it so that you can check to see if it is necessary to defragment the drive. Analyzing the volume only takes a minute and prevents your wasting valuable time defragmenting a drive that is not fragmented. Although defragmenting a drive that is hardly fragmented at all does not hurt the drive, it uses up system resources unnecessarily. Sometimes, when you are viewing the disk defragmenter analysis bar graph, it looks as if there are system files on volumes other than the system and boot volumes, because the Master File Tables (MFT) and paging files appear as system files within the disk defragmenter. This occurs because they cannot be moved; they are opened for exclusive use by Windows 2000 at all times and therefore cannot be defragmented. Windows 2000 reserves a portion of free space on the beginning of the drive for the Master File Tables (MFT), which contain all the information necessary to retrieve files from the volume. The Master File Tables cannot be moved because there is no way for Windows 2000 to know where they have gone.

Analyzing a Drive

To analyze a drive once it is in the disk defragmenter, click the Analyze button, or click the Action menu from the toolbar and choose Analyze. If you need to pause or stop the drive analysis once it is running, you can click the Stop or Pause button as required. Once the analysis is complete, a dialog box will pop up with the details of the analysis and recommendations as to whether or not you should defragment the drive (see the following figure. If you would like more information on the volume analysis, click the View Report button.

This is the disk defragmenter Analysis Complete dialog box.

Viewing Reports

If you click the View Report button after analyzing a volume, the disk analysis report will be displayed. In the following figure, the disk is 17 percent fragmented, so disk defragmentation is recommended. When the average fragments per file is more than 1.02, the disk defragmenter will suggest that you defragment your volume. The analysis report is a text-based version of the analysis display. It includes volume information such as the volume size, the amount of free space, and the amount of fragmented files and folders. It also displays the average number of fragments per file. The average number of fragments per file is a good indicator of how fragmented the files on the disk are. This can be viewed if you scroll down in the Volume Information area. The best figure possible is 1.00, indicating that all or most files are contiguous. If the average number of fragments is 1.10, that means that 10 percent of the files are fragmented, which means that approximately 10 percent of the files are in two pieces instead of in one contiguous area. There is also a separate section including details about the most fragmented files: the path, the number of fragments, the file size, and the file names. Windows 2000 tells you whether you should defragment your drive and allows you to save or print the analysis.

Once you are finished viewing the analysis report, click Defragment to start the defragmenting process or click Close to return to the disk defragmenter screen.

This is a disk drive analysis.

TOPIC 4: Defragmenting NTFS File System Partitions

If it is recommended that you defragment your drive, click the Defragment button or choose the Action menu from the toolbar, followed by Defragment, and the defragmenting will start immediately. Once the disk defragmenting has been completed, a dialog box pops up informing you that Windows 2000 has finished defragmenting your drive (see the next figure). From here, you can either view the defragmentation report or you can close that dialog box.

This is the Defragmentation Complete dialog box.

The defragmentation report looks very similar to the analysis report. It lists the volume information, including the cluster sizes, used space, free space, and fragmentation percentage. It also lists the most fragmented files, including details about the number of fragments, the file sizes, and the file names. You can print, save, or close the defragmentation report when you are finished viewing it. When files are moved about the volume, it causes the disk defragmenting process to be restarted, which slows down the process. The disk defragmenter can have an impact on performance, so it is best to run the disk defragmenter when the computer is not being used or is being used only minimally. You should defragment highly accessed volumes, such as file servers, more frequently than those hardly in use, such as extra workstations, because the more frequently a volume is accessed, the more fragmented it becomes.

TOPIC 5: File and Folder Permissions

Windows NTFS permissions are used to assign access rights to files and folders. These access rights define who can access the files and folders and what they can do with the contents. NTFS permissions are only available when NTFS volumes are used and are not available with alternative file systems such as FAT or FAT32. The types of access you can assign to a folder are different from the options available for

NTFS Folder Permissions

NTFS folder permissions are used to assign access controls to a folder. The following table is a summary of folder permissions and the access control they provide. A user or group can have one or more folder

files.

permissions.

NTFS Folder Permissions

Folder permission Read

Write

List folder Contents

Read & Execute

Modify

Full Control

NTFS File Permissions

they enforce.

NTFS File Permissions

File permission Read

Write

Read & Execute

Modify

Full Control

Allows Users can see the files and subfolders in the directory. They can also view the ownership, attributes, and permissions on the file. Users can create new files and subfolders, and can change the folder’s attributes and view ownership and permissions. Users can see the names of files and subfolders in the folder. Users can browse through the folder, opening folders to which they may not have explicit access. They also have Read and List Folder Contents on the files and subfolders. Users can delete the folder in addition to the actions provided by the Write and Read & Execute permissions. User can perform the actions of all other permissions, and can take ownership, change permissions, and delete files and subfolders.

Allows Users can view the ownership, permissions, attributes, and contents of a file. Users can change the file’s attributes or overwrite the file completely, and can view the file’s ownership and permissions. Users can perform the actions provided by Read, and can execute the file if it is an application. Users can perform the actions provided by the Write and Read & Execute permissions, and can modify or delete the file. Users can perform the actions provided by all other permissions, and can change permissions and take

NTFS file permissions are applied to the files contained in the folders. NTFS file permissions may be more restrictive or more lenient than the permissions on the folder that contains the file and thus may alter the user’s effective access permissions. This table summarizes access permissions and the restrictions

ownership.

How Windows 2000 Applies NTFS Permissions

Only an administrator, the owner, or a user with Full Control permissions can change the NTFS file and folder permissions. Before trying to adjust the permissions on a folder, ensure that you have the right access privileges.

Access Control Lists

Windows NTFS uses an access control list (ACL) to define who can access a file or folder and the type of access they have. An ACL is composed of multiple access control entries (ACEs). Each ACE corresponds to the access permissions for a single user or group. When a user attempts to access a file or folder, that user’s ID and group membership list are compared to the file’s or folder’s ACL. If there is a match, then the user has the permissions defined by the ACE. If the requested action matches those allowed by the assigned permission, then the action will be completed.

Combining NTFS Permissions

A user may have multiple ACEs that define that user’s access permissions. For example, a user may have been assigned specific permissions, and one or more of the user’s groups may also have been provided access permissions. In order to understand the behavior of NTFS file permissions, you need to understand the rules governing the combination of permissions and the inheritance rules of NTFS. Many common permissions-related problems occur when administrators do not understand the rules.

Permissions Are Cumulative

When determining a user’s access to a specific resource, Windows 2000 calculates the user’s effective permissions. The effective permissions are the sum of all access permissions defined in the ACL. If multiple entries match the access the user has been granted—for example, Read for the user’s specific account ID and Write for a group of which the user is a member—then the effective permissions are Read and Write.

File Permissions Override Folder Permissions

When determining access to a resource, Windows 2000 will let file permissions override folder permissions. A user may not have any access permissions to a folder, but may have full control access to a file contained in that folder. The user would not see the file in a folder listing but could use a full Universal naming convention (UNC) path—for example, \servername\project\restricted\sales.doc—to gain access to the file. This lets administrators and users essentially create hidden, editable files. Users browsing the network will not see the files, but those who know that those files exist can access and update them. This is an extreme example. More commonly, an administrator might create a folder to which no one has Write access, and then specifically provide Write access to one or more files to certain users.

Deny Overrides All Other Permissions

The Deny permission completely overrides any other access permissions a user may have. This contradicts the cumulative rule, but provides a powerful means to ensure that a folder is properly secured. An administrator or user with appropriate permissions can specifically deny a user or group access to a file or folder. This ensures that no groups of which the user is a member can gain access to the file or folder. When used with a group, the Deny permission applies to all members of the group.

Note

While the Deny permission is a powerful security tool, it can be extremely difficult to use in environments with complex group interrelations. In environments where users are members of every group or where there is heavy nesting of groups, administrators may find it difficult to use the Deny permission without blocking out more people than were intended.

Permission Inheritance

By default, permissions are inherited from the parent folder. This makes it easier to administer a shared folder environment by ensuring that any new files and folders created in the folder have the same access control lists as the parent. Users need not worry about adjusting the permissions on new folders and files. It is possible to disable this behavior in Windows 2000. Stopping permission inheritance is like stopping a progression of events at a given time and resetting the clock before starting again. If you stop the inheritance on a given folder, you can set its permissions to something different from those of the parent. Any new folders or files will inherit the permissions, unless the permissions are otherwise configured by the user.

Assigning NTFS Permissions

Permissions should be assigned after careful planning. Administrators should grant NTFS permissions strictly on the basis of user need. Adding users or groups to the ACL without careful planning may result in users’ obtaining access to data they should not have. There are three stages to assigning permissions:

Planning NTFS permissions Managing permissions Assigning special access permissions

Planning NTFS Permissions

If you take some time to plan a strategy for using NTFS permissions carefully, you will find them easy to use, flexible, and extremely powerful. When you develop your strategy or plan, keep these points in mind:

Group files according to their type. Separate applications from public and project-related data. Assign each user a home directory for storing personal information. Centralize the data as much as possible, and always store it on a partition that is separate from the operating system. This makes OS upgrades and system repairs easier to manage. Assign permissions to folders instead of to files. Assign only the access permissions a user needs to complete a specific job. Create groups and assign permissions to them. Assign permissions to user accounts only when it is absolutely necessary. Use the Deny permission only when it is absolutely needed. The overuse of Deny permissions can often create confusion when users are unable to access folders and files. Teach users how to use access permissions to control access to files. NTFS permissions are a powerful tool for both protecting and sharing data.

Managing NTFS Permissions

When an NTFS file system is created, the default permission is for the Everyone group to have Full Control. You should take some time to change the permission sets and inheritance on critical folders. To change the NTFS permissions of a file or folder:

  1. Right-click the object and select Properties.

  2. Click the Security tab (see below).

This is the Security tab of the Folder Properties Window.

  1. From here you can see the access permissions of each user or group by clicking on its name. Adjust the permissions as needed.

To add a user:

  1. From the Security tab, click the Add button.
  2. Select the user or group by double-clicking on its name. You can add multiple groups simultaneously (see the following figure).
  3. Click OK to close the Add window.
  4. Select the group in the Security tab and set the desired permissions.

Use the Add User window to add users and groups to the access control list (ACL) of a file or folder.

To prevent the inheritance of permissions from the parent folder:

  1. Right-click the file or folder and select Properties.
  2. Click the Security tab.
  3. Uncheck the Allow Inheritable permissions from parent to propagate to this object.
  4. You will be prompted to choose from copying the previously inherited permissions, removing the inherited permissions, or aborting the operation (see the next figure).

When you remove the inherited permissions option, you must choose whether to copy or delete the previous permissions.

  1. Select the one of the options: Copy will copy over the inherited permissions from the parent folder. Remove will remove all inherited permissions; retaining only those permissions you have explicitly selected (see below). Abort cancels the operation.
  2. Click OK to close the Properties window.

Inheritance has been turned off, with the option to remove all previously inherited permissions.

Special Access Permissions

Windows 2000 provides 12 special access permissions that give you additional capabilities beyond the normal access permissions of the ACL. Two useful special access permissions are Take Ownership and Change permissions.

Take Ownership

Every object (whether in the Active Directory or in an NTFS volume) has an owner. The owner controls how permissions are set on an object. When an object is created, the creator automatically becomes its

owner. Administrators will create and own most objects in Active Directory. Users will create and own data files in their home directories and on network servers. Using the Take Ownership special access permissions is one way to transfer ownership of a file or folder from one user to another. A user can be granted the right to take ownership. Administrators always have the right to take ownership of a file or folder. The rules governing the Take Ownership permissions include:

The current owner of the file or folder, or any user with Full Control permissions on the file, can either assign Full Control or take Ownership permissions to another user or group, allowing them to take ownership of the file or folder. Administrators can always take ownership of a file or folder, regardless of the permissions on the file. When an administrator takes ownership, the administrator group becomes the owner. Any member of the administrator group can then assign either Full Control or Take Ownership permissions to another user or group.

Note

Ownership of files and folders cannot be assigned under Windows 2000. You must use the take Ownership permissions to transfer the ownership of a file from one user to another. In some cases this may be a two-step process in which the administrator takes ownership of a file and assigns the Take Ownership permission to another user, who then takes ownership. The most common use of the Take Ownership permission occurs when one employee assumes responsibility for a project and the associated data files from another employee. Either the current owner or the administrator must assign the Take Ownership privilege to the new owner, who can then use these privileges to assume ownership of the data. This method of assigning Take Ownership permissions and having the new owner explicitly take ownership of the data has advantages over other systems in which ownership of objects and files can simply be changed. First, this method ensures that the previous owner of the data does not lose ownership without explicitly granting someone else the rights to take it. Second, it lets the new owner choose which data to own. Someone cannot assign ownership of data or any Active Directory object without the knowledge of the new owner.

Change Permissions

The Change Permissions special access permission lets you give other users the ability to change permissions on a file without giving them full control. This gives the users some flexibility in defining the permissions on the files without completely opening the access to the object. One situation in which such a feature might be useful is a large project that involves several teams. The project leader might create a master directory for the entire project and then create subfolders for each team. In order to allow a team leader some flexibility in managing access to individual folders, the project manager might grant the team Change Permissions access. The project manager may not want to grant full control, to prevent the team leaders from changing the directory structure. Granting Change Permissions allows the team leader some flexibility in defining access to the files on an as-needed basis without giving them complete control over the entire directory structure.

Other Special Permissions

The following table is a complete list of special access permissions, along with a short description. Special access permissions provide administrators with flexibility in controlling access to resources on the network and should be a part of every administrator’s tools.

Special Access Permissions and Their Functions

Special access permission Description

Traverse Folder/Execute FileBrowse folder contents or open an application (Execute).
List Folder/Read DataSee the contents of a folder or file (List Folder Contents/Read).
Read AttributesView the attributes of a file or folder.
Read Extended AttributesView the extended attributes of a file or folder.
Create Files/Write DataCreate a new file (Write).
Create Folders/Append DataCreate a subfolder or append data to a file (Write).
Write AttributesModify the attributes of a file or folder.
Write Extended AttributesModify the extended attributes of the file.
Delete Subfolders and FilesDelete files and folders from a directory.
Read PermissionsView permissions of a file or folder.
Change PermissionsModify the permissions of a file or folder.
Take OwnershipTake ownership of a file or folder.

Using Special Access Permissions

The special access permissions allow you to define access to folders and files in more detail, along with granting permission to Take Ownership or Change Permissions. Windows 2000 combines multiple special access permissions to form the regular permissions set.

Setting the Special Access Permissions

The special access permissions are accessed much as are regular permissions. They can be thought of as advanced security settings. To set the special access permissions:

  1. Right-click the folder or file for which you want to change the permissions and select Properties.
  2. Click the Security tab.
  3. Click the Advanced button to open the Access Settings dialog box (see below).

This is the Advanced Security Setting window.

  1. Ensure that the Permissions tab is selected.
  2. Select the user for whom you want to change the permissions and click View/Edit (see below).

This is the special access permission window for a particular user.

  1. Adjust the permissions and click OK.
  2. Click OK to close the Advanced Settings window.
  3. Click OK to close the Properties window. Tip You can use the option “Apply these Permissions to Objects and/or Container Within This Container Only” to specify whether subfolders and files contained in the folder inherit the special permissions from the folder. When you check this box, the permissions will propagate. Clear this check box to prevent inheritance.

Taking Ownership of Files and Folders

Once you have granted special access permission to take ownership, the user can follow a similar series of steps to take ownership of the files. To take ownership of a file or folder, follow these steps:

  1. Right-click the folder or file for which you want to change permissions and select Properties.
  2. Click the Security tab.
  3. Click the Advanced button.
  4. Select the Owner tab (see below).

The Owner tab of the Access Control Settings allows you to take ownership of a folder and its contents.

  1. In the Change Owner To: field, select the user you want to designate as the new owner.
  2. Check the Replace Owner on Subcontainer and objects to change the owner on all subfolders and files.
  3. Click OK to close the Access Control Settings window.

Changing NTFS Permissions

When you change the permissions on an object, the new permissions apply when the object is subsequently accessed. If a user has the object open at the time when the permissions are changed, the user is allowed access according to the permissions that were in effect when the object was opened. Explicit permissions on an object can be directly changed by user action, but inherited permissions cannot be changed directly. Thus, to change permissions on a file whose permissions are inherited, you can do either of the following:

Change the permissions on the parent object, and specify that the changed permissions should be propagated. Add permissions to an object that has inherited permissions, giving the object a combination of both explicit and inherited permissions. For example, if a file inherits Read and Write permissions from its parent, and then you add Delete permission to the file, the file now has the cumulative permissions of (Read and Write) and (Delete).

TOPIC 6: Copying and Moving Files and Folders

When files are copied or moved, the permissions on the file may change. Understanding the rules that govern when the permissions will change is critical to managing access to your data. Administrators and users often set the access permissions of a file or folder and then move or copy the object without realizing that the permissions may have changed.

Copying Files

The following table shows what happens to file and folder permissions during a copy. Copying files will always affect the permissions on the file, because Windows treats the copied file as a new file. In order to copy files between NTFS partitions or between folders on the same partition, you must have Write permissions to the destination. You will also become the creator-owner of all copied objects.

Effects on Permissions of Copying a File or Folder

ActionEffect on permissions
Copy a file or folder to another location onThe file or folder will inherit the permissions of the
the same NTFS partition.folder to which it is being copied.
Copy a file or folder to a location on aThe file or folder will inherit the permissions of the
different NTFS partition.folder to which it is being copied.
Copy a file or folder to a FAT partition.All permissions are lost.

Warning

When files are copied to FAT partitions, all NTFS permissions are lost. FAT partitions have no way of storing or understanding NTFS permissions.

Moving Files

The next table shows what happens to file and folder permissions during a move. When files or folders are moved, the permissions do not always change. The specific exception is when you move a file or folder from one location on an NTFS partition to another location on the same partition. The reason for this difference in the behavior of permissions is subtle but critical. When you move a file on the same partition, Windows 2000 simply updates the file pointers and structures to reference the file’s new location. When you move a file to a different partition, Windows 2000 actually copies the file from the old partition to the new one and then deletes the original file. The file on the new partition is essentially a new file, and new files always inherit the permissions from the parent folder. When you move a folder within an NTFS partition:

The folder or file will retain all NTFS permissions currently defined. You must have Write permissions to the destination folder. You must have Modify permissions on the original folder, because Windows 2000 will delete the source folder once it has written the data to the new location. You will become the creator-owner of the file or folder.

When you move a file or folder between NTFS partitions, these rules apply, but the files or folders inherit the permissions of the destination folder.

Effects on Permissions of Moving a File or Folder

Action Effect on permissions Move a file or folder to another location on the same The permissions will remain the same. NTFS partition. Move a file or folder to a location on a different NTFS The file or folder will inherit the permissions partition. of the folder to which it is being copied.

Move a file or folder to a FAT partition. All permissions are lost.

Warning

When you move a file or folder to a FAT partition, all NTFS permissions are lost.

F Foorr M Ma an naag ge errss O Onnlly y The reason we build networks of computers is to create environments where users can share ideas, collaborate on projects, and gain access to additional information resources. Sharing resources on your network will become an everyday occurrence and eventually will be a critical part of your business
development process.A robust infrastructureWhen you build network and server infrastructures, keep these ideals of collaboration in mind. The key components to an effective information sharing strategy are: Effective tools and resources to facilitate sharing of ideas Windows 2000 provides the starting point for building a robust server and network environment. It offers solutions that can vary in scale from small workgroups to large enterprises. The Active Directory provides a central repository for storing all user account, group, shared resources, and computer objects. Using Active Directories lets Windows 2000 scale across multiple sites and geographical regions. Yet all this power is not lost on the small workgroup in which the supplied tools minimize the administrative
project.overhead. tremendous.With server environments like Windows 2000 and Active Directories, network administrators can build an extensive and robust environment to facilitate the sharing of data and ideas between users. By creating a mix of public and project-related folders designed to meet user needs, the administrator creates a natural environment where users store the relevant data in locations accessible by everyone on the Without centralized shared resources, users would be forced to use the pint-to-point file sharing built in to Windows NT and 95/98. This model is potentially feasible in small environments, but it is full of problems. First, there is no centralization of user account information. With Windows NT Workstation or Windows 2000 Professional, user may quickly fall into the habit of creating local user accounts. In a Windows 95/98 environment, users can only assign a Read or Write password. The next problem is the potential complexity of configuring the shared folders. Many users may be overwhelmed by the complexity of configuring shared folders under Windows 2000 or NT. To avoid the complexities they will leave the permissions wide open, with everyone having Full Control permissions. This makes it impossible to enforce any kind of universal security on critical business data. Finally, one of the worst problems is the scattering of data all over the network, with no logical organization or layout. This makes it difficult for new users to find the data. They may have to search through multiple servers located all over the company looking for bits and pieces of the project data. Investment in the time and effort needed to plan a shared data strategy will pay off in several ways. It will significantly reduce the amount of administrative overhead by concentrating the administration to a smaller number of servers. Centralization will improve the overall security of your environment, because things will be managed under a single set of rules in a centralized environment. Finally, the increases in the productivity of users who are able to collaborate with colleagues will be

Sharing Resources

Sharing folders (see the following figure) over the network makes the contents of the folders accessible to other users on the network. Shared folders offer another level of security to control access to the files and folders on a computer. Shared folder access permissions apply not only to NTFS partitions but also to FAT and FAT32 partitions.

This is a shared folder in Windows 2000. Securing Network Resources you can assign to a shared folder. Shared Folder PermissionsWindows Explorer uses a folder with a hand underneath to represent a shared folder. To control access to shared folders, you assign the shared object access permissions. The following table lists the permissions
Share permissionsActions allowed
ReadSee folder names, file name, data, and attributes, run applications.
ChangePerform all the actions of the Read permissions; create files and folders, change files, append to files, delete files and folders, and change file attributes.
Full ControlPerform all the actions allowed by Change permissions; change permissions and Take Ownership.

While shared folders do offer an extra layer of security, there are issues to keep in mind when you develop a strategy for sharing data over the network. These include:

Shared folder permissions apply only to folders. You cannot share files individually. Shared folder permissions generally allow less detailed control over access than do the native Windows NTFS permissions. Shared folder permissions do not apply to users who have gained physical access to the machine and logged on locally. The Default permissions on a shared folder are Full Control for the Everyone group.

You can allow or deny any of the shared folder permissions to both users and groups. The best practice is to assign Allow permissions to groups and generally avoid denying permissions except when you specifically need to lock out a user who is a member of a group with access permissions. If you deny users access, it will override any access permissions granted to groups of which they are members.

Shared Folder Permissions

As with NTFS permissions, there are a series of rules and guidelines to follow in applying shared folder permissions. Many of the guidelines are the same, but there are a few new ones with shared folders. When applying shared folder permissions, keep in mind:

Permissions are cumulative. If a user is a member of multiple groups, each with unique access permissions, the user’s effective permissions will be the combination of all the group access permissions. Deny overrides all other permissions. As with NTFS permissions, Deny overrides any other permissions assigned to the user or any group of which the user is a member. On NTFS volumes, the user must have access via the NTFS permissions in addition to the shared folder permissions. On a FAT volume, shared folder permissions are the only security control that determines the user’s access to the data in the folder. On an NTFS

partition, the user must have the appropriate permissions in order to access the files and folders in the shared folder. When a shared folder is copied or moved, it is no longer shared. This is true no matter where it is copied or moved.

Creating Shared Folders

While it is easy to just jump right in to Windows 2000 and begin creating shares, as with most administrative tasks, planning a strategy can significantly reduce the amount of overhead involved in managing shares across your network. Develop a strategy that takes into account the types of data you want to share (project or individual) and who will have access to the data. Once you have a strategy in place, the process of creating and managing shares is relatively quick and easy.

Developing a Shared Folder Strategy

The best way to reduce the administrative overhead of creating and managing shared folders is to plan a strategy. The first step is to identify what types of files and folders you want to share. You can share out both applications and data. The benefit of shared applications is that you can ensure that every user is running the same version of an application, or you can upgrade every user to a new version simultaneously. Having shared data allows users to collaborate on projects. Almost no one works in an isolated environment anymore. Most business activities require a high degree of coordination and collaboration among individuals and teams. Without a strategy that clearly defines what resources will be shared and who can access them, you will find yourself constantly adjusting share permissions or moving data around trying to accommodate the business processes in your environment.

Shared Applications

Shared applications are the easier of the two types of shared folders to create. Shared application folders are created on a network server and contain network-runnable versions of the applications. Even with the application on the network, often some customization or settings data still is stored on each machine. Before beginning the process of sharing applications, ask each vendor how that vendor’s application will work in such an environment. Each application will work slightly differently and may require some slight adjustment. When creating shared folders for applications:

Try to organize all your shared applications under a single folder. This makes it easier to manage installs and upgrades. It also makes it easier for users, because you only have to point them to one place for all their applications. Assign Read permissions to the Users group or some other group that you have created for this purpose. This ensures that the users you create will have access to the applications folder. Remove the Everyone group from the access list. This keeps out users you have not specifically placed in a group that has access. Also, the Everyone group has Full Control permissions, which grant the right to delete or change files in shared folders. Add a group to the access list with Full Control privileges. This can be the built-in Administrators group or some other group you have designated as the one you want to do the administrative tasks. If needed, you can add additional groups with Change privileges who can update applications or troubleshoot user problems, depending on the size of your organization and its specific needs.

Shared Data

Data folders are used for sharing both public and project-related data. Project data is shared by small workgroups or teams working on a specific task. Public data requires more general access by the entire community of users. You will probably have a mix of public and project data on your servers. For best performance and to ease administration, keep shared data on a separate volume from the operating systems and applications. This makes it easier to clearly identify the data that needs regular backups. As always, an effective data management strategy makes backups and restores an essential component. When you build shared data folders:

Centralize the data as much as possible and as reasonably supported by your server infrastructure. This makes it easier to administer and back up. Ensure that the administrator group or an equivalent has Full Control access to the folders for maintenance purposes. Create separate folders for each major project or class of information. Use group access permissions to assign the appropriate groups the access levels they need to each folder (Read, Change).

Sharing Folders

In Windows 2000 the following built-in groups have the user rights to create shared folders: administrators, server operators, and power users (Windows 2000 Professional edition). To determine on which machines these groups have the right to create a shared folder, use these rules:

In a Windows 2000 domain, the administrators and server operators can create a shared folder on any machine in the domain. Since Power Users is a local group, the members can only create shares on the server or workstation where the ID exists. In a workgroup situation, the Administrator and Power Users groups can create shared folders on the server or workstation that they reside on. Before creating a share on an NTFS partition, you must ensure that you have at least Read access to the folder.

Administrative Shares

Depending on the configuration of the computer, some or all of the special shares may appear when Windows 2000 presents a list of shared resources. Special shares are created by the system and should not be deleted or modified. Windows 2000 creates several administrative shares by default. These shares are used for remote administration and are normally hidden from the nonadministrative users. All administrative shares end with a $. This table provides a list of administrative shares and their use.

Administrative Shares and Their Use

Share namePurpose
<drive_letter> or D$A share that allows administrators to connect to the root directory of a storage device. For example, D$ is a share name by which drive D might be accessed by an administrator over the network. For a Windows 2000 Professional computer, only members of the Administrators or Backup Operators group can connect to these shares. For a Windows 2000 Server computer, members of the Server Operators group can also connect to these shares.
ADMIN$A resource used by the system during remote administration of a computer. The path of this resource is always the path to the Windows 2000 system root, for example, C:\Winnt.
IPC$A resource sharing the named pipes used for communication between programs. It is used during remote administration of a computer and when viewing a computer’s shared resources.
REPL$This resource is created by the system when a Windows 2000 Server computer is configured as a replication export server. This resource is used only by Windows 2000 Servers that are configured as replication export servers.
NETLOGONUsed by the Net Logon service of a Windows 2000 Server computer while processing domain logon requests. This resource is used only by Windows 2000 Server.
PRINT$This share is created the first time you install a printer and points to the systemroot\System32\Spool\Drivers folder. The administrator, server operators, and print operators have Full Control permissions. The Everyone group has Read privileges. This share is used to distribute printer drivers to users when they install a printer from the server.

Note

You can create additional hidden shares by appending a $ to the end of the share name. Users can access the folder only if they know the name of it and have the proper permissions.

Creating a Shared Folder

When you configure a shared folder, you have a number of options:

Share name Description Limit the number of users who can connect Set permissions

Tip You can share the same folder a number of times with different names and access privileges.

To create a shared folder:

  1. Right-click the folder you want to share and select Sharing (see below).

This is the Sharing tab of the Properties window.

  1. Click Share this folder.
  2. Configure the sharing options (see the following table).
  3. Click OK to close the Property window.

Options for a Shared Folder

OptionPurpose
Share NameThe name users will use to access the shared folder.
CommentAn optional description of the contents of the folder. User will see the comments when browsing the server with the View options set to Details mode.
User LimitYou can limit the number of users accessing the shared folder concurrently. Under Windows 2000 Professional, the limit is set to 10 concurrent users. With Windows 2000 Server, you can support an unlimited number of users, within the limits of the number of Client Access Licenses you own.
PermissionsAllows you to define the permissions on a shared folder. By default, the Everyone group has Full Control permissions
CachingSettings used for offline access to the shared folder

Assigning Permissions to a Shared Folder

Once you have created a shared folder, you need to assign access permissions to the folder. By default, the Everyone group has Full Control permissions. When you work with shared folders on NTFS partitions, you must also consider the NTFS permissions. To assign permissions to a shared folder:

  1. Open the Sharing tab of the Properties window by right-clicking on the shared folder and selecting Sharing.
  2. Click the Permissions button (see the following figures).
  3. Click the Add button to open the Select Users, Computers, or Groups window (see below).
  4. Double-click the users and groups you want to add to the share permissions of the folder.
  5. Click the Add button.
  6. Select each user you added and click the share setting you want to either allow or deny to them.
  7. Click OK to close the Properties window.

The Permissions window is used for setting shared folder permissions.

The Add Users, Computers, or Groups window is used for adding users and groups to the access permissions of a folder.

Note

To add users from other domains, click the Look in drop-down list of the Add Users, Computers, or Groups window to display a list of domains. You can search the entire Active Directory by selecting Entire Directory from the list.

Managing Shared Folders

Shared folders are managed completely from the Share tab of the Folder Properties window. From this window you can start or stop sharing on a folder, limit the number of users, share the folder under another name, or modify its permissions. When managing shares:

If you stop sharing on a folder while a user has files open, the user may lose data. Be sure to disconnect all users using the share before you stop the share. When you click Do Not Share This Folder while a user is connected, Windows 2000 will display a warning dialog (see the next figure). You will need to confirm stopping the share.

The Confirmation dialog is used to stop folder sharing while users are connected to the folder.

To view a list of shares, sessions, or open files:

  1. Open Computer Management from the Start-Programs-Administrative menu (see below).
  2. In the console tree, click Shares, Sessions, or Open Files.

Computer Management interface is used for viewing shares, sessions, and open files.

Note

Files opened by other users are displayed, but files opened by you are not.

Note

When you are administering another computer remotely, your connection appears as an open named pipe. It cannot be closed.

Connecting to a Shared Folder

There are three ways in which users typically connect to a shared folder: through the run command, through mapping a drive, or through using My Network Places browser (Network Neighborhood under Windows NT and 95/98). Each method is perfectly valid, and the one you select will depend on need and user technical skill. The Run command is most often used when users know the Universal Naming Convention (UNC) path of the files or folder they want to access. A typical UNC path has the syntax \<share><folder>\…<folder/file>. An example would be \wallace\public\hrforms\hiring.doc, which is a reference to a Word document called “hiring.doc” on the server “wallace” in a share called “public” in a folder called “hrforms.” A user who does not know the full UNC path but knows the domain and server name may choose to use the My Network Places or the Network Neighborhood to browse for the machine on the network, using the Graphical User Interface. The interface is easy to navigate, allowing the user to double-click the server and its shared folders in search of the desired file. Finally, mapping a drive is a method often used when the administrator wants to simplify the interface for the user or when an application must work with a logical drive reference instead of with the network-based UNC paths. When you map a drive to a network folder, Windows 2000 creates a new drive letter within the My Computer folder that takes you directly to the network folder when it is double- clicked. To connect using the Run command:

  1. Click the Start menu and select Run.
  2. Type the Universal Naming Convention (UNC) path into the Open field (see below).
  3. Click Run.

The Run command is used with a UNC to open a shared folder.

Tip The Run command offers a useful and powerful shortcut capability. When a UNC is entered, the Run command has the ability to look ahead inside the directory specified to provide a list of subfolders. This is extremely helpful when you forget the exact folder name. You can enter part of he name, click the arrow, and the Run command will present a list of subfolders (see the next figure).

As you enter a UNC path, the Run command looks ahead inside the server and share directories to display a list of subfolders.

To connect to a shared folder using the drive-mapping wizard shown in the next figure:

  1. Right-click the My Network Places icon on the desktop and select Map Network Drive. If you test from a Windows NT or 95/98 machine, use the Network Neighborhood icon.
  2. Select a drive letter. Windows 2000 will by default select the first open letter.
  3. Enter the UNC path of the shared folder.
  4. Click the Finish button to create the mapped drive.

This is the drive-mapping wizard.

You can also map a drive using the Net Use command from the command line in Windows 2000. Net Use maps a drive letter to a share name. When it is used with no command line options, it will display a list of all current network connections. The syntax for Net Use is:

Net use <drive_letter>

Net use h: \wallace\public</u>

One powerful option under the Net Use command is the ability to specify an alternative username and password. By adding the /user flag, you can specify a different username than the currently active logon name. This allows a user to connect as an alternative ID without having to log off and log on. For those that want to use a graphical interface to browse the network and locate a server, Windows 2000 offers the My Network Place interface, an update of the Network Neighborhood found in earlier versions of Windows. To use My Network Place:

  1. Double-click the My Network Place icon on the desktop.
  2. Locate the server that contains the shared folder.
  3. Double-click the shared folder to open it.

TOPIC 7: NTFS Permissions and Shared Folders

When folders are shared on FAT partitions, the shared folder permissions are the only permissions in effect. When you share folders on an NTFS partition, you can use both the NTFS and sharing permissions to control access to the folders. When you combined shared folder and NTFS permissions, the more restrictive permissions are always the effective permissions for the user. The following table provides an example of both share and NTFS permissions, along with the effective permissions each user needs in order to access the folder over the network. In this case, listed users are not members of any listed groups and there are no other access control Entries besides those listed. One effective permission that stands out is that Kathy Jones cannot access the folder over the network despite the fact that she is the owner of the file on the NTFS partition. If she were to access the file by sitting at the server and logging on, she would have Full Control.

Combining Share and NTFS Permissions to Determine Effective Permissions

User/GroupNTFS permissionShare permissionEffective Permission
Jsmith “John Smith”No AccessFull ControlNo Access
TestersFull ControlReadRead
EngineersFull ControlChangeChange
AdministratorFull ControlFull ControlFull Control
Kjones “Kathy Jones”Full Control (Owner)No AccessNo Access

NTFS permissions offer administrators more flexibility in defining access control to both files and folders. Share permissions offer fewer options and apply only at the folder level. One common strategy for managing the combination of shared and NTFS permissions is to leave the default Everyone with Full Control shared permission. NTFS permissions are then used to control access to subfolders and files. The other advantage of this strategy is that NTFS permissions apply both locally and over the network. This ensures that users who gain access to the machine and logs on locally have no greater access to data files than if they had connected over the network. This combination of permissions is often one of the most confusing aspects of access control for new Windows 2000 administrators. Each set of permissions, shared and NTFS, is cumulative. When permissions are combined, the more restrictive set of permissions becomes the user’s effective permission.

Guidelines for Managing Shared Folder Permissions

Managing shared folder permissions can be a time-consuming task if it is done haphazardly. To ease administration of shared folders and improve security:

Determine the resources you will make available over the network Identify the groups that need access to each resource and the type of access they need. Assign permissions to groups instead of to users. This makes it easier to manage access and determine who has access. Grant the minimum level of access required to get the job done. If a group only needs to be able to read the contents of the files, then assign only Read permissions. Use intuitive names for shared folders, keeping in mind the client platforms that will require access to the shared folder.

Note

Windows 2000, NT, and 95/98 have a length limit of 12 characters when they display shared folder names in the network neighborhood graphical interface. DOS and Windows 3.11 clients

are limited to eight character share names, Longer share names can be accessed using the Run command or by using the mapped drive functions.

Tip While Windows 2000 offers the ability to create 8.3 filename equivalents, these names are generally not intuitive. If you will be supporting DOS and Windows 3.11 clients, create share names that meet the limitations of these platforms.

TOPIC 8: Encrypt and Decrypt Files

EFS uses a public key pair and a secret key in the encryption/decryption process. When a user tries to encrypt a file, EFS determines whether a user key pair is in existence for the user, or whether it must be created. If a key pair needs to be created, the generation occurs on a domain controller or on the local computer. Other tasks completed by EFS include creating the actual ciphered file, ciphering the File Encryption Key, creating a log, creating a backup file, and deleting the log and backup file used in the encryption process. In order to manage encrypted file resources, the user must first identify what data needs to be protected, and then use either Explorer or the Cipher command utility to encrypt the file. Any folder or file, as long as it is stored on a NTFS volume, can be encrypted by the owner. The easiest way to maintain encrypted files is to first create an encrypted folder where you plan to store all sensitive data. After creating the folder, right-click on the directory and select Properties. Click ADVANCED on the General tab, which then displays the Advanced Attributes window. Check the “Encrypt contents to secure data” box. The process for encrypting an individual file is identical, except that the file should be selected first before right-clicking to navigate to Properties. Any newly created file or subdirectory stored in the marked encrypted directory from this point on will be automatically encrypted. If the directory is marked for encryption and it already contains existing files and subdirectories, the user receives a message asking whether to encrypt files and subdirectories in the directory. A tradeoff exists between compressed and encrypted files: a file can only be encrypted or compressed, not both. The encryption process will fail if a file that has the system bit set is targeted for encryption.

Decrypting a File

The decryption process occurs when a user accesses an encrypted file during normal operations. The file is unencrypted on the fly, though the file remains encrypted on the disk. Windows 2000 will also go through the decryption process when the owner of the file decides that the added security method is no longer needed. When the user wants to read and/or modify the contents of the encrypted file, the Windows 2000 operating system decrypts the file as it is moved from the hard drive into physical memory. The decryption of the file for use is transparent to the user, and the ciphered file is still stored on the hard drive. The user does not have to decrypt the file manually before each use. EFS must have the user’s private key in order to decrypt the file. To permanently decrypt a file, the user can use the Explorer interface and clear the encryption attribute, or use the Cipher Utility and execute the appropriate command. When an individual file is selected for decryption, only that file is affected. When the user at the directory level requests decryption, a message is displayed, asking whether the user wishes to decrypt all files and subdirectories found within this directory. This decryption process at the directory level is exactly like the process for changing permissions at the directory level. Use these steps to decrypt a file:

  1. Using Explorer, select the file you want to decrypt, and right-click to bring up the Context menu.
  2. Select Properties, and click ADVANCED on the General tab.
  3. In the Advanced Attributes dialog box, clear the check box to “Encrypt contents to secure data.”
  4. Click OK. On the General tab, click OK or APPLY to mark the file as unencrypted.

TOPIC 9: Data and Directory Compression

Windows 2000 data compression is much like packing your summer wardrobe into one part of your closet until next season. Your summer clothes and shoes are spread out throughout your closet and dresser drawers, but at the end of the summer, you pack them away for the winter. When you pack them, you roll your clothes and pack your socks inside your shoes, and squish as much as you can into one part of your closet. The clothes have not changed in dimension, but they take up a smaller area. This is essentially what Windows 2000 data compression does. It takes the files and folders that you seldom use (your summer clothes) and compresses them into a smaller package (packing them more tightly so that they fit in a small part of your closet rather than being spread throughout your room). This way, they take up less space on your drive and leave more room for new files and folders (your new winter clothes). Data compression decreases the amount of disk space required for file storage so that you can add either more data or new applications. Data compression is available only for drives formatted with the NT file system (NTFS). Compression can be performed on files, folders, or whole NTFS volumes. After a file is compressed, when you want to access it, you don’t have to decompress it manually; it is decompressed automatically by Windows 2000 before it is available for use. The same thing happens after you are finished with a file and you save it. The file is recompressed automatically by Windows 2000.

Compressing Files and Folders

To compress a file or folder, right-click it. Select Properties from the pop-up menu and then choose the Advanced button. There are four check boxes to choose from in the Advanced dialog box. Choose the “Compress contents to save disk space” check box and then click OK (see the figure below). To uncompress a file or folder, simply remove the check mark from the check box and click OK.

This is the Advanced Attributes dialog box for a folder on an NTFS volume.

It is possible to compress a folder, but not the files and subfolders within it. You might want the files already in a folder to remain uncompressed, but you want new files to be compressed. There are two ways to do this. You can either compress every new file as you add it to the folder, or you can compress

the folder so that all files added to the folder will be compressed automatically. When you are compressing a folder, the Confirm Attribute Changes dialog box will ask if you want the compression applied to the files and subfolders within the folder that you are compressing (see below).

In this case, the Confirm Attribute Changes dialog box confirms the compression attributes.

There are two options when you compress a folder:

Apply changes to this folder only. This option will compress only the folder, not any files or subfolders below it. It will pass on the changes in compression state to any files and subfolders copied into the folder in the future. Apply changes to this folder, subfolders, and files. This option will pass down the changes in compression state to all the subfolders and files within it as well as to any files and subfolders copied into the folder in the future.

If you choose to change the compression status for the subfolders and files as well as for the folders, you will see a dialog box showing the compression status for each file and subfolder as it changes (see the next figure). You can click Cancel if you decide that you no longer want to perform this action. If you cancel the action before the compression has been completely applied, the folders that already received the compression attribute will remain compressed, but unchanged files and/or folders will remain unchanged.

The Compression Status dialog indicates the time remaining.

When you want to change the compression state of a file or folder, you must have the proper permissions for that particular file or folder. To change compression status, you will need at least write permission for that file or folder.

Determining Compression Status

There are several ways to determine if a file or folder is compressed. You can right-click the file or folder, select Properties and then the Advanced button, and view the attribute properties. Alternatively, you can configure the color scheme for compressed and uncompressed files and folders. Compression status is not displayed with an alternate color by default, but you can configure it in Windows Explorer. To change the color that indicates compression status, open Windows Explorer, choose the Tools menu, and then choose Folder Options. Click the View tab and select the “Display compressed files and folders with alternate color” check box (see below).

In Files and Folders you can choose to display compressed folders in an alternate color.

Click Apply or OK to apply the changes. Once you have done this, the compressed file and folder names will appear in blue, while the uncompressed file and folder names will remain in the system colors you have defined (see the following figure).

In this Windows Explorer window, an alternate color is used to display only the compressed folders Inetpub and temp.

You can also compress an entire volume by going into My Computer or Windows Explorer and choosing the volume that you would like to compress. Right-click Volume and select Properties from the pop-up menu. From the General tab, you can configure Windows 2000 to compress the entire drive (see the next figure). It is best to compress data that is accessed infrequently, to reduce system degradation.

You can compress an entire volume/disk from within the General tab of the Local Disk

Properties dialog box.

Disk Space Requirements

Disk space is allocated on the basis of the uncompressed size of files and folders, because when you want to view, edit, or move a compressed file, NTFS automatically uncompresses it, lets you use it while it is uncompressed, and then recompresses it when you are finished. Therefore, if you want to copy a compressed file to another drive, you need to make sure that there is enough room for the file when it is uncompressed; otherwise you will get an error message stating that there is not enough room for the file on the destination drive.

Compression State

The compression state for a folder does not necessarily represent the compression state for the files and subfolders beneath it. For example, an uncompressed folder can contain several files that are compressed, or it can be compressed but contain several uncompressed files and subfolders. Consequently, when you are checking the compression status of your files and folders, you must check each individual file to determine its compression state. This is why the color differentiating for compressed and uncompressed folders is so helpful. If the color differentiating is enabled, you can see the compression state of each file and folder without having to go into the properties of each one.

Compression Rules

Compressed files and folders cannot be encrypted. NTFS encryption and compression are mutually exclusive. Therefore, if you encrypt a file, you cannot compress it, and if you compress it, you cannot encrypt it. Windows 2000 also only supports compression for cluster sizes under 4 KB, because compression on larger clusters can cause performance degradation. If you try to compress data on a volume with a larger cluster size, you will notice that compression is not an option and is therefore not available for that particular volume. You cannot compress files on FAT partitions, because FAT partitions do not support Windows 2000 file compression.

Copying and Moving Compressed Files and Folders

In Windows 2000, as in Windows NT 4.0, there are rules that determine the compression state when you move and copy files and folders within and between volumes. There are also rules that determine the compression state when you move and copy files and folders between FAT and NTFS partitions. Compression is a feature of NTFS volumes only and cannot be performed on a FAT volume. Copying compressed files and folders can cause performance degradation, because Windows 2000 uncompresses the file, copies it to the new location, and then compresses the file again.

Copying a File within an NTFS Volume

When a file is copied from one folder to another folder within an NTFS volume, the compression setting for the file changes to that of the target folder. Copying a file is like creating a new file in the target folder, so it will take on the attributes of the target folder. For example, if you copy an uncompressed file into a compressed folder, the file will be automatically compressed (see the following figure).

When data is copied within an NTFS volume, the data inherits the compression attributes of the target folder.

Moving a File or Folder within an NTFS Volume

When a file or folder is moved from one folder to another within an NTFS volume, the compression setting is retained. For example, if you move an uncompressed file into a compressed folder on the same volume, the file will remain uncompressed (see the next figure).

When data is moved within an NTFS volume, the data retains its compression attributes

regardless of the compression status of the target folder.

Copying or Moving a File or Folder between NTFS Volumes

When a file or folder is copied or moved from one folder to another on different NTFS volumes, the compression setting for the file changes to that of the target folder. Once again, this happens because when you copy or move a file from one volume to another, it has to create the file at the target and then delete it from the source, so it takes on the attributes of the folder in which it is created (see the next two figures).

When data is copied between NTFS volumes, the data inherits the compression attributes of the target folder.

When data is moved between NTFS volumes, the data inherits the compression attributes of the target folder.

Moving or Copying a File or Folder from an NTFS Volume to a FAT Volume or to a Floppy Disk

When a file or folder is moved or copied to a FAT volume, it is automatically uncompressed, because FAT does not support Windows 2000 file compression (see the next figures). Floppy disks also do not support compression, as the information needed to support the NTFS file system cannot fit on a floppy, so floppies end up being FAT.

When data is moved or copied from an NTFS volume to a FAT volume, the data is automatically uncompressed.

When data is moved or copied from an NTFS volume to a floppy disk, the data is automatically uncompressed.

TOPIC 10: What Can Go Wrong, Will…

Troubleshooting Access Problems

Troubleshooting access problems can be tedious at times, and as an administrator you must take some time to fully understand the interaction between NTFS and share permissions. One of the most common mistakes administrators make is to actively grant Full Control access to users to overcome file permission problems that cannot be resolved. This slowly erodes the security of your server, and everyone on the network winds up with Full Control access to every piece of data. There are a few easy steps you can follow to develop a strategy for managing NTFS permissions and shares that can dramatically simplify the process of assigning and troubleshooting access permissions.

Solving Permission Problems

The types of problems administrators and users encounter are small but can often have one of many possible causes and solutions. Don’t assume, if two people are having the same problem, that the root cause is the same.

The three general categories of problems presented here are the most common; users either have too few or too many access rights, or you are not getting the expected behavior when you configure permissions.

Users cannot access a file or folder. You add a user account to a group with access permissions, but the user still cannot access the file or folder. Users with Full Control access to a folder can delete files and subfolders to which they do not have access.

Troubleshooting permission problems is just like troubleshooting any other administrative problem. It is necessary to follow a series of specific steps to narrow the realm of possible causes, in order to find the root cause; then methodically apply solutions to determine which one has the desired result. When you fix permissions problems, be careful not to start with solutions that open up broad access on the affected shared or folder. This creates a new problem without really resolving the initial problem.

If a user loses access to a file or folder that was recently copied or moved to a new location, the folder probably inherited an ACL that has no ACE for the user or a group to which the user belongs. When a user account is added to a group, the user must either log off or disconnect from the server before it will pick up the group membership change. Have the user log off and log back on. The Full Control permission includes the special access permission Delete subfolders and files. You have two options; either lower the permissions the user has to the folder or, through the Special Access Permission dialog, remove the user’s ability to delete subfolders and files.

Always use NTFS partitions on your Windows 2000 Server. FAT partitions do not offer the access control features of NTFS and pose a potential security risk.

Assign the most restrictive access permissions that still lets users get their work done. Assign permissions at the folder level. Group related files into separate folders and restrict access to the folders. This reduces the number of objects for which you have to manage access permissions and reduces the possibility that a file will get less restrictive permissions than the folder it is in. File permissions override folder permissions. Ensure that users have Read & Execute permissions only for executable applications. This prevents applications from becoming damaged by virus or malicious user activity. The administrator should retain change permissions so that the application can be updated when needed. Use the Creator Owner built-in system group to improve security and flexibility. Give the creator-owner Full Control access while limiting others to the needed permissions. This ensures that a user who creates a subfolder or file has access to modify and delete it and, for files and folders created by other users, will have only the access granted via either inherited permissions or those specifically set by the creator of the file. Assign rights as high in the container tree as possible. You gain the greatest breadth of effect with the least effort. Apply inheritance to propagate rights through the container tree.

TOPIC 11: Handy File & Directory Tools and Links

Cipher Utility

Windows 2000 provides users with a command-line interface for file encryption. The general format of the Cipher Utility is:

>cipher [ /e] [ /d] [ /s [dir]] [ /a] [ /i] [ /f] [ /q] [filename]

When the cipher command is executed without any switches or filename, the result will be a display of the encryption status of the current directory and any files in that directory. Typing cipher /? at the command prompt will display the switches that can be used with the command.

Recovery Operations

Windows 2000 contains an Encrypted Data Recovery Policy (EDRP), which is part of the local security policy in a workgroup environment or part of the domain security policy for domains. The Security Subsystem in user mode is responsible for the enforcement of this policy. This subsystem is responsible for caching the EFS policy so that the policy can be applied offline. A first step is to ensure that the System Administrator sets up a Recovery Policy. Windows 2000 contains a Recovery Agent Wizard, in which Recovery Agents are assigned along with their corresponding key pairs. The Microsoft Base Cryptographic Provider is used to create a Data Recovery File for each Recovery Agent. To recover an encrypted file that the owner cannot manipulate:

  1. The person responsible for the recovery operation—the Recovery Agent—should use a Backup utility and restore a copy of the user’s ciphertext file on the computer that has the recovery certificates.
  2. Using Explorer, the encrypted file’s Properties should be displayed.
  3. On the General tab click ADVANCED.
  4. The clearing of the Encrypt contents to secure data check box will use the Recovery Agent’s private key and decrypt the file. The decrypted file should now be backed up and restored to the user. Note that recovery keys can be exported as a file and stored on different physical media, such as floppy disk. A command-line utility can also be used to recover an encrypted file. If you decide to use the EfsRecvr utility, the same steps should be applied in order to back up the file and restore it on the computer that contains the recovery keys. The EfsRecvr command-line utility uses this general format:
EFSRECVR [ /S [:dir]] [ /I] [ /Q] [ filename […]]

TweakUI Utility

You cannot choose the color for compressed files to be viewed by default, but you can do so with a Microsoft utility called TweakUI (see the following figure). TweakUI is a Windows NT Powertoy that provides access to many hidden registry keys in Windows 95/98/NT/2000. One feature of this utility allows you to set the compressed data color to a different color. Powertoys were developed by Windows developers in their spare time. They are not officially supported by Microsoft, although they work very well. You can find TweakUI by browsing http://www.microsoft.com/windows and looking for Windows NT or 2000 power toys.

The Explorer tab of the TweakUI utility includes the option to change the color of compressed files at the bottom of the dialog box.

Document3 4/3/02 4:04 PM Page 1