Active directory Users with Home Folders on a CIFS Share.

Status
Not open for further replies.

yoyojazz

Cadet
Joined
Aug 16, 2012
Messages
7
Hi everyone,

I hope anyone can help or atleast tell me if it is at all possible?

I have build a freenas box up adding Active directory and CIFS services and all is good.
I can see my users and groups on the Freenas web gui and I can assign the CIFS Share (HOME)i created Windows Admin credentials as Owner and domain admins as Group.
I give RWX to both Admin and Domain admin group and for everyone else I choose to give RX .

Ok I am now creating users in my AD and i decide to use this freenas to house all the users home folders.

I go to the 2008 R2 DC (Users and Computer) select my user and go to his profile and then create a \\freenas\HOME\%username%

This will automatically create me a folder with the name of the user.

When i try OK this I have error messages explaining that the permissions cannot be set etc etc.

I don't want to create a duplicate set of users in Freenas just to do Home Directories.
I just wanted to authenticate using my windows credentials to access this CIFS share and AS i have full permission I would like to create my AD users folders and prescribe the appropriate permissions so that users can only see their drives and save and write work to it from the AD.

Has anyone done this before has anyone had any problem with permissions etc or have a document as to how best to set them on freenas so that when accessing a share in windows I can ask window to assign the necessary permissions?

Thank you for taking the time out to read my query.

Cheers

Jazz
 

yoyojazz

Cadet
Joined
Aug 16, 2012
Messages
7
Result

Hi think I got it working i was looking at it the wrong way and applying permissions all wrong by over complicating things.

What i was initially doing was assigning my domain admin and admin group to the share i created but using the AD feature which worked but I was also trying to assign the everyone permission on the share and by making it recursive and inheritable when i logged into windows and created Home$ shares with each user name it ALREADY had a Special permission in there for everyone to view and execute files.

So what i done on freenas was only assign User and Group privileges but did not assign ANY privileges for everyone.

Logged via my AD to the freenas share and accessed the Home Share and added the everyone group from there to have read and write access to that "Subfolder only" So everyone could browse to that and that alone.

I would create home profiles the usual way on the AD (Users and Computer) with the \\freenas\home$\%username%

This created a folder with the users name. This folder automatically had permissions for Admin, Admin group (Full Control) and the Domain User to create files but everyone cannot get access to this private subfolder.

This seemed to have worked for me.

Cheers

Jazz
 
Status
Not open for further replies.
Top