6-0 Files and Folders

6 Files and Folders
Exam Objectives in this Chapter:
■ Configure access to shared folders
❑ Manage shared folder permissions ■ Configure file system permissions
❑ Verify effective permissions when granting permissions
❑ Change ownership of files or folders ■ Troubleshoot issues related to access to files and shared folders ■ Manage a Web server
❑ Manage Internet Information Services (IIS) ❑ Manage security for IIS
Why This Chapter Matters Among the more common daily challenges facing you as an administrator are tasks related to the maintenance of network files and folders—resources that are required by users in your organization. When a user cannot access a resource that he or she needs to achieve a business task, the telephone at the help desk rings. As a result, you spend time and money modifying permissions or group member-ships to correct the problem. When a sensitive resource is accessed by someone who should not be able to do so, the telephone on your desk rings—and as a result, you might have to spend time and money looking for a new job. You have no doubt experienced the fundamental components of resource security in Windows technologies—the assigning of access permissions to users or groups. Microsoft Windows Server 2003 offers enhancements, nuances, tools, and capabilities beyond the feature set of Windows 2000 and Windows XP, and strikingly different than Windows NT 4. Each of these additions will affect the best practices for managing and troubleshooting files and folders. In this chapter, you will review the concepts and skills related to managing shared folders, and examine the useful Shared Folders snap-in. You will explore the Access Control List Editor, or ACL editor, with its multiple dialog boxes, each of which supports important functionality. After examining a variety of permission 6-1
6-2 Chapter 6 Files and Folders configurations, you will evaluate effective permissions, the resulting set of permissions for a user based on user and group permissions, you will configure auditing to monitor for specific file access and operations. Finally, you will turn to IIS, which, like the File and Print Sharing service, offers another way to provide net-work access to files and folders. Lessons in this Chapter: ■ Lesson 1: Setting Up Shared Folders. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-3 ■ Lesson 2: Configuring File System Permissions.. . . . . . . . . . . . . . . . . . . . . 6-13 ■ Lesson 3: Auditing File System Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-31 ■ Lesson 4: Administering Internet Information Services. . . . . . . . . . . . . . . . . 6-38
Before You Begin
This chapter presents the skills and concepts related to computer accounts in the Microsoft Active Directory directory service.. If you want hands-on practice, using the examples and lab exercises in the chapter, prepare the following:
■A Windows Server 2003 (Standard or Enterprise Edition) installed as Server01 and configured as a domain controller in the contoso.com domain.
■ First-level organizational units (OUs): Security Groups and Employees
■The Domain Users group must be a member of Print Operators so that, during lab exercises, “normal” users can log on to a domain controller.
■Five domain local security groups in the Security Groups OU: Project 101 Team, Project 102 Team, Engineers, Managers, and Project Contractors.
■User accounts in the Employees OU for Scott Bishop, Danielle Tiedt, and Lorrin Smith-Bates, with Scott Bishop belonging to the Engineers, Project Contractors and Project 101 Team groups, Danielle Tiedt belonging to the Engineers and Project 101 Team, and Lorrin Smith-Bates belonging to the Managers and Project 101 Team.
■Access to the Shared Folders snap-in through the Computer Management console, File Server Management console (available via Manage Your Server), or a custom MMC console.



