You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Windows文件共享使文件夹可见但非授权用户无法进入

How to Keep ControlledFolder Visible in GeneralShare but Restrict Access to Approved AD Users

Alright, let's break this down—this is a super common scenario where you want a folder to show up in a shared drive but lock out anyone not in a specific AD group. The trick here is combining Windows' two permission layers: Share Permissions and NTFS Permissions correctly on your Server 2016 box.

Step 1: Set Up Share Permissions for GeneralShare

First, we need to make sure all authenticated AD users can see the contents of GeneralShare (including ControlledFolder) without giving them full access. Here's how:

  • Open Server Manager > Go to File and Storage Services > Click Shares
  • Right-click GeneralShare > Select Properties > Switch to the Permissions tab
  • Clear out any overly restrictive permissions that might block visibility (like explicit Deny entries)
  • Add Authenticated Users to the permissions list, and grant them the Read share permission. This lets them browse the share's contents and see that ControlledFolder exists.
  • Keep the default full control permissions for Administrators and SYSTEM—you don't want to mess with those.

Step 2: Lock Down NTFS Permissions for ControlledFolder

This is where we restrict actual access to the folder's data. NTFS permissions take precedence over share permissions, so this is our main security layer:

  1. Navigate directly to the ControlledFolder on your server's filesystem (the one inside GeneralShare's root directory)
  2. Right-click the folder > Properties > Switch to the Security tab
  3. Click Advanced to open the Advanced Security Settings window
  4. First, click Disable inheritance > Choose Convert inherited permissions into explicit permissions on this object. This ensures we don't inherit loose permissions from the parent GeneralShare folder.
  5. Remove any permissions for groups/users that shouldn't access the folder (like Authenticated Users, Everyone, or random user accounts)—only keep Administrators and SYSTEM for now.
  6. Click Add > Select a principal > Type in ControlledFolderAccess (your AD group) > Click Check Names to verify it exists > Hit OK
  7. For this group, grant the permissions you need—common picks are Read & Execute, List Folder Contents, and Read (or Modify if they need to edit files inside).
  8. Make sure the Apply to dropdown is set to This folder, subfolders and files (adjust only if you have a specific need to limit permissions to just files or the root folder).
  9. Click OK to save all your changes.

Step 3: Test the Setup to Confirm It Works

Don't skip this part—always verify with both authorized and unauthorized users:

  • Log in as a user not in the ControlledFolderAccess group. Navigate to \\YourServerName\GeneralShare—you should see ControlledFolder listed. Try opening it, and you should get an "Access Denied" error (perfect, that's exactly what we want: visible but no access).
  • Log in as a user in the group. You should be able to open ControlledFolder and access its contents without any issues.

Quick Pro Tips

  • Never use explicit Deny permissions unless you have no other option—NTFS permissions are granular enough to restrict access without Deny, which can cause unexpected conflicts.
  • If you ever need to adjust permissions later, always start with NTFS first, then check share permissions if something isn't working.
  • Keep a backup of your permission settings before making big changes—just in case you need to roll back.

内容的提问来源于stack exchange,提问作者Thomas Ward

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:44:36