Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , ,

Sponsored Links



Hiding Sysvol and Netlogon shares?

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 05-11-2009
foxj77
 
Posts: n/a
Hiding Sysvol and Netlogon shares?

Hi there,

Is it possible to hide the sysvol and netlogon shares on our windows
domain network?

We have a windows domain on a subnet and another standalone server on
the same subnet that will be managed by someone else. I am just
carrying out some tests and from the standalone server and they are
able to browse the shares and write files to the sysvol share!!

Is there anyway i can secure these two shares? is it possible to put
a $ on the end of the share to hide it?

Anyone any ideas on what is possible? I don't want to come in one day
to find that the domain has gone down because someone has messed up
the sysvol share!

Thanks
Reply With Quote
  #2  
Old 05-11-2009
Florian Frommherz [MVP]
 
Posts: n/a
Re: Hiding Sysvol and Netlogon shares?

Howdie!

foxj77 wrote:
> Is it possible to hide the sysvol and netlogon shares on our windows
> domain network?
>
> We have a windows domain on a subnet and another standalone server on
> the same subnet that will be managed by someone else. I am just
> carrying out some tests and from the standalone server and they are
> able to browse the shares and write files to the sysvol share!!
>
> Is there anyway i can secure these two shares? is it possible to put
> a $ on the end of the share to hide it?


Those shares are used by a number of functions within Windows Server and
Windows clients. I wouldn't wanna mess with them and hide them, move
them, whatever.

Since those folks have access to the shares, I would investigate why
they have that sort of access in the first place - are they in security
groups they shouldn't be in? Tailor down their permission by removing
them from priviledged groups or customize security on both shares (test
that thoroughly!)

Cheers,
Florian
Reply With Quote
  #3  
Old 05-11-2009
Meinolf Weber [MVP-DS]
 
Posts: n/a
Re: Hiding Sysvol and Netlogon shares?

Hello foxj77,

Leave them alone, they are essential for functioning domain. The only one
able to mess up with them are the administrators, users are NOT able to change
anything there.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi there,
>
> Is it possible to hide the sysvol and netlogon shares on our windows
> domain network?
>
> We have a windows domain on a subnet and another standalone server on
> the same subnet that will be managed by someone else. I am just
> carrying out some tests and from the standalone server and they are
> able to browse the shares and write files to the sysvol share!!
>
> Is there anyway i can secure these two shares? is it possible to put
> a $ on the end of the share to hide it?
>
> Anyone any ideas on what is possible? I don't want to come in one day
> to find that the domain has gone down because someone has messed up
> the sysvol share!
>
> Thanks
>



Reply With Quote
  #4  
Old 05-11-2009
foxj77
 
Posts: n/a
Re: Hiding Sysvol and Netlogon shares?

On Nov 5, 10:03*am, Meinolf Weber [MVP-DS] <meiweb@(nospam)gmx.de>
wrote:
> Hello foxj77,
>
> Leave them alone, they are essential for functioning domain. The only one
> able to mess up with them are the administrators, users are NOT able to change
> anything there.
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!!http://www.blakjak.demon.co.uk/mul_crss.htm
>
> > Hi there,

>
> > Is it possible to hide the sysvol and netlogon shares on our windows
> > domain network?

>
> > We have a windows domain on a subnet and another standalone server on
> > the same subnet that will be managed by someone else. *I am just
> > carrying out some tests and from the standalone server and they are
> > able to browse the shares and write files to the sysvol share!!

>
> > Is there anyway i can secure these two shares? *is it possible to put
> > a $ on the end of the share to hide it?

>
> > Anyone any ideas on what is possible? *I don't want to come in one day
> > to find that the domain has gone down because someone has messed up
> > the sysvol share!

>
> > Thanks


The seperate server i am trying to access them from use to be part of
the domain. It looks like i have the same admin user locally as my
domain admin account and possible something to do with cached
credentials or something weird with kerbos.

When I create a new local admin users I cannot see anything and things
are fine!
Reply With Quote
  #5  
Old 05-11-2009
Florian Frommherz [MVP]
 
Posts: n/a
Re: Hiding Sysvol and Netlogon shares?

Howdie!

foxj77 wrote:
> The seperate server i am trying to access them from use to be part of
> the domain. It looks like i have the same admin user locally as my
> domain admin account and possible something to do with cached
> credentials or something weird with kerbos.


Dublicate local users with equal passwords wouldn't end in such a
result, either. I suspect you have those users in an over-priviledged
AD-groups (possibly Domain Administrators) and their logging on with
those creds. You should investigate what group membership they have
(whoami /all is something you can do while they're logged on)

Cheers,
Florian
Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Hiding Sysvol and Netlogon shares?"
Thread Thread Starter Forum Replies Last Post
Sysvol/netlogon shares never created new dc2008 bdavis Active Directory 1 1 Week Ago 12:26 AM
Missing SYSVOL and NETLOGON Terry Windows Server Help 3 06-11-2009 02:16 PM
netlogon and sysvol shares missing mike Active Directory 12 21-10-2009 09:01 AM
sysvol and netlogon problem kyrnel Operating Systems 1 13-08-2007 12:22 PM
missing sysvol and netlogon Dan in Kalamazoo Windows Server Help 1 13-02-2007 07:22 AM


All times are GMT +5.5. The time now is 05:16 PM.