Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > File Systems > RE: How To for Access Based Enumeration Permissions?

Reply
Thread Tools Display Modes

RE: How To for Access Based Enumeration Permissions?

 
 
John Angel [MSFT]
Guest
Posts: n/a

 
      09-26-2008

Hi Mark,

You can use DFSUtil.exe to setup ABDE (Access Based Directory Enumeration)
in your namespace. The command line you should use is like this:

DFSUtil Property ABDE \\YourDomain\YourNamespace

This allow the users to view the links only for which they have permissions.

You can type DFSUtil Property ABDE to get more information.

"Mark Olbert" wrote:

> Like apparently quite a few others, I'm having trouble getting access based enumeration to work. This is using a DFS setup on Server
> 2008 (standard). Basically, all the "component" shares in the DFS share I set up are visible to all users all the time. They can't
> access folders they don't have rights to, but the folders themselves are still visible.
>
> Is there an "official" how to for setting the permissions correctly? I gather one has to be careful about what permissions are
> granted to both the share and the links in the DFS root. But I'm not clear on just what they should be.
>
> - Mark
>

 
Reply With Quote
 
 
 
 
DaveMills
Guest
Posts: n/a

 
      09-27-2008
But which permissions get tested? The DACL on the DFS folder/reparse point, the
one on the target share or both.

On Fri, 26 Sep 2008 16:06:01 -0700, John Angel [MSFT]
<> wrote:

>Hi Mark,
>
>You can use DFSUtil.exe to setup ABDE (Access Based Directory Enumeration)
>in your namespace. The command line you should use is like this:
>
>DFSUtil Property ABDE \\YourDomain\YourNamespace
>
>This allow the users to view the links only for which they have permissions.
>
>You can type DFSUtil Property ABDE to get more information.
>
>"Mark Olbert" wrote:
>
>> Like apparently quite a few others, I'm having trouble getting access based enumeration to work. This is using a DFS setup on Server
>> 2008 (standard). Basically, all the "component" shares in the DFS share I set up are visible to all users all the time. They can't
>> access folders they don't have rights to, but the folders themselves are still visible.
>>
>> Is there an "official" how to for setting the permissions correctly? I gather one has to be careful about what permissions are
>> granted to both the share and the links in the DFS root. But I'm not clear on just what they should be.
>>
>> - Mark
>>

--
Dave Mills
There are 10 types of people, those that understand binary and those that don't.
 
Reply With Quote
 
John Angel [MSFT]
Guest
Posts: n/a

 
      09-29-2008
ABDE is related to the DFS root. Once it's enabled it shows to the user only
the links for which he has permissions. Basically you set ABDE and then you
set the ACLs against a DFS link.

"DaveMills" wrote:

> But which permissions get tested? The DACL on the DFS folder/reparse point, the
> one on the target share or both.
>
> On Fri, 26 Sep 2008 16:06:01 -0700, John Angel [MSFT]
> <> wrote:
>
> >Hi Mark,
> >
> >You can use DFSUtil.exe to setup ABDE (Access Based Directory Enumeration)
> >in your namespace. The command line you should use is like this:
> >
> >DFSUtil Property ABDE \\YourDomain\YourNamespace
> >
> >This allow the users to view the links only for which they have permissions.
> >
> >You can type DFSUtil Property ABDE to get more information.
> >
> >"Mark Olbert" wrote:
> >
> >> Like apparently quite a few others, I'm having trouble getting access based enumeration to work. This is using a DFS setup on Server
> >> 2008 (standard). Basically, all the "component" shares in the DFS share I set up are visible to all users all the time. They can't
> >> access folders they don't have rights to, but the folders themselves are still visible.
> >>
> >> Is there an "official" how to for setting the permissions correctly? I gather one has to be careful about what permissions are
> >> granted to both the share and the links in the DFS root. But I'm not clear on just what they should be.
> >>
> >> - Mark
> >>

> --
> Dave Mills
> There are 10 types of people, those that understand binary and those that don't.
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
DFS Access Based Enumeration ABE Rich File Systems 8 11-13-2008 04:56 AM
Access Based Enumeration on DFS Mirco Wilhelm File Systems 2 03-28-2008 03:45 PM
Access Based Enumeration FletchInRaleigh Server Networking 3 09-04-2006 10:48 PM
Access Based Enumeration Matthew Loraditch Windows Server 1 11-03-2005 09:20 AM
Access-based Enumeration Server Security 1 09-09-2005 01:41 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59