Start a Conversation

This post is more than 5 years old

Solved!

Go to Solution

699

October 3rd, 2016 08:00

Moving over windows shares and ntfs perms

Ok a little confused on something. So looking at moving over various windows shares currently on 2008 and 2012 boxes. Almost all of them have access granted via AD groups. Some dept shares have subfolders that are not shares where inheritance is turned off and access to that is granted via another AD group. So the dept generates the data and outside users are able to access that particular folder.

Typically all our shares uses the same AD groups for both the share and ntfs permissions and ABE is set on all shares. When I look in OneFS I get that I need to 1st create the folder under file system explorer then go to protocols and create the share. I can then add the same AD groups to the share side there.

My question though is really about the equivalent ntfs side. On all our shares now, some have inheritance off, and Everyone, Domain users etc are all removed. Domain Admins is added along with the various AD groups. For the Isilon, would I do the same thing by going to like \\isiview1\ifs\data\isidata\Depts~ and then managing my various folders permissions on the security tab like in windows? Ive tested on one share and seems to work fine.

I turned off inheritance under advanced and removed the items I didn't want, added those I did. The for any subfolders within that where only certain users need access I repeated.

Is this correct?

thx

2 Intern

 • 

20.4K Posts

October 10th, 2016 09:00

should be no different from how you manage things today. I treat \\isilon_cluster\ifs  just like you would \\server\c$.  I locked down ifs share with permissions so that only system admins can connect. From that point on in the root of \ifs i create a folder that corresponds to my cluster name (helpful for future DR/Replication), then i create a folder for each access zones (helpful for future auditing) and then underneath each zone name i create a folder for each department, remove inheritance and add AD groups per my requirements.

October 12th, 2016 11:00

Great thx for confirming that for me.

No Events found!

Top