如何配置Windows文件共享使文件夹可见但非授权用户无法进入
Alright, let's break this down—this is a super common scenario where you want a folder to show up in a shared drive but lock out anyone not in a specific AD group. The trick here is combining Windows' two permission layers: Share Permissions and NTFS Permissions correctly on your Server 2016 box.
Step 1: Set Up Share Permissions for GeneralShare
First, we need to make sure all authenticated AD users can see the contents of GeneralShare (including ControlledFolder) without giving them full access. Here's how:
- Open Server Manager > Go to File and Storage Services > Click Shares
- Right-click
GeneralShare> Select Properties > Switch to the Permissions tab - Clear out any overly restrictive permissions that might block visibility (like explicit Deny entries)
- Add
Authenticated Usersto the permissions list, and grant them the Read share permission. This lets them browse the share's contents and see that ControlledFolder exists. - Keep the default full control permissions for
AdministratorsandSYSTEM—you don't want to mess with those.
Step 2: Lock Down NTFS Permissions for ControlledFolder
This is where we restrict actual access to the folder's data. NTFS permissions take precedence over share permissions, so this is our main security layer:
- Navigate directly to the
ControlledFolderon your server's filesystem (the one inside GeneralShare's root directory) - Right-click the folder > Properties > Switch to the Security tab
- Click Advanced to open the Advanced Security Settings window
- First, click Disable inheritance > Choose Convert inherited permissions into explicit permissions on this object. This ensures we don't inherit loose permissions from the parent GeneralShare folder.
- Remove any permissions for groups/users that shouldn't access the folder (like
Authenticated Users,Everyone, or random user accounts)—only keepAdministratorsandSYSTEMfor now. - Click Add > Select a principal > Type in
ControlledFolderAccess(your AD group) > Click Check Names to verify it exists > Hit OK - For this group, grant the permissions you need—common picks are Read & Execute, List Folder Contents, and Read (or Modify if they need to edit files inside).
- Make sure the Apply to dropdown is set to This folder, subfolders and files (adjust only if you have a specific need to limit permissions to just files or the root folder).
- Click OK to save all your changes.
Step 3: Test the Setup to Confirm It Works
Don't skip this part—always verify with both authorized and unauthorized users:
- Log in as a user not in the ControlledFolderAccess group. Navigate to
\\YourServerName\GeneralShare—you should see ControlledFolder listed. Try opening it, and you should get an "Access Denied" error (perfect, that's exactly what we want: visible but no access). - Log in as a user in the group. You should be able to open ControlledFolder and access its contents without any issues.
Quick Pro Tips
- Never use explicit Deny permissions unless you have no other option—NTFS permissions are granular enough to restrict access without Deny, which can cause unexpected conflicts.
- If you ever need to adjust permissions later, always start with NTFS first, then check share permissions if something isn't working.
- Keep a backup of your permission settings before making big changes—just in case you need to roll back.
内容的提问来源于stack exchange,提问作者Thomas Ward

