Конфигуриране на споделен достъп до файлове при Server 2012 / Configuring shared file access in Windows Server 2012.
!!!За да изпълните упражнението е необходимо да имате инсталиран софтуер за виртуализация и виртуална машина работеща с Windows Server 2012. Софтуерът за виртуализация използван в текущото упражнение е VMWare vSphere!!!
1. Въведение
- Целта на това практическо упражнение е да се усвоят основните методи за конфигуриране на споделен достъп до файлове при Windows Server 2012. Студентите ще усвоят знания свързани с процеса по споделяне на ресурси посредством файлов браузър и посредством Server Manager.
2. Цел на упражнението
- Споделяне на папки и файлове посредством файлов браузър;
- Споделяне на папки и файлове посредством Server Manager;
3. Споделяне на папки и файлове посредством файлов браузър
- Стъпка 1. – Стартирайте виртуалната машина.
Стъпка 2. – При това и при следващите упражнения ще работите със компютри, които са добавени в една обща област – MADomain.test. В рамките на тази област, можете да достъпите всеки от шестте компютъра (MAServer1, MAServer2, MAServer3, MAServer4, MAServer5 и MAServer6) посредством локален потребител Administrator с парола MAPassword123. В рамките на областта, можете да използвате дефинираните потребители – Administrator и Student, които използват парола MAPassword123.
Стъпка 3. – За компютъра, на който ще работите, използвайте мрежов профил MADomain.test/Administrator с парола MAPassword123. След успешен вход в системата, минимизирайте Server Manager и стартирайте файлов браузър.
1. Introduction
- The purpose of this practical exercise is to present to the students the main methods for configuration of shared file access in Windows Server 2012. The students will obtain knowledge about the process for sharing resources through the file browser and using the Server Manager.
2. Aim of the exercise
- Sharing of folders and files with the file browser;
- Sharing of folders and files with Server Manager;
3. Sharing of folders and files using the file browser
-
Step 1. – Start the virtual machine
Step 2. – In this and in the next exercises you will work with computers that were joined in the domain – MADomain.test. In the domain, you can access every of the six computers (MAServer1, MAServer2, MAServer3, MAServer4, MAServer5 and MAServer6) through the local user account Administrator with password MAPassword123. In the network domain you can use the user accounts – Administrator and Student, which are using password MAPassword123.
Step 3. – For the computer, on which you are working, use the network wide account MADomain.test/Administrator with password MAPassword123. After the successful access to the system, minimize Server Manager and start the file browser.

- Стъпка 4. – Използвайте файловия браузър (File Explorer) и създайте нова папка Accounting на дисков дял “C:\”.
- Step 4. – Use the file browser (File Explorer) and create a new folder Accounting on partition “C:\”.

- Стъпка 5. – В папка Accounting създайте нов празен текстов файл (New > Rich Text Document) и го наименувайте Budget. Отворете файла с WordPad и въведете произволен текст в него. Запазете промените за файла.
- Step 5. – In folder Accounting, create new empty text file (New > Rich Text Document) and rename it as Budget. Open the file with WordPad and enter any random text in it. Save the changes in the file.

- Стъпка 6. – Изберете с десен бутон папката Accounting и от контекстното меню изберете Properties. На екрана ще се зареди диалогов прозорец с настройки за папката.
- Step 6. – Select with the right button the folder Accounting and from the context menu choose Properties. On the screen you will see a dialog window with the settings for the folder.

- Стъпка 7. – Изберете таба Sharing и натиснете бутона Advanced Sharing. Ще се появи диалоговия прозорец с настройки за споделяне на папката.
- Step 7. – Select the Sharing tab and press the button Advanced Sharing. A new dialog window will appear that will contain the settings for the sharing of the folder.

- Стъпка 8. – Изберете полето за маркиране Share This Folder и за полето за въвеждане на текст Share Name променете стойността по подразбиране Accounting на Spreadsheets.
- Step 8. – Select the Share This Folder option and in the text entry field for the Share name change the value from Accounting to Spreadsheets.

- Стъпка 9. – Изберете бутона Permissions. Ще се зареди диалогов прозорец Permissions For Spreadsheets. Изчистете маркиранията в колона Allow за групата от потребители Everyone.
- Step 9. – Select the button Permissions. A new dialog window – Permissions For Spreadsheets will be displayed. Clear out the marked values in the column Allow for the user group Everyone.

- Стъпка 10. – Изберете бутона Add. Ще се зареди диалогов прозорец Select Users or Groups. В полето Enter the object names to select въведете Domain Admins и изберете OK. Групата на администраторите за мрежовата област ще се появи в полето Group Or User Names на диалоговия прозорец Permissions For Spreadsheets. Маркирайте групата Domain Admins и маркирайте Full Control в колоната Allow. Това действие ще маркира автоматично и Change полето. Изберете бутона Apply.
- Step 10. – Select the Add button. This will open the Select Users or Groups dialog window. In the entry field Enter the object names to select enter the Domain Admins value and select OK. The group for the administrators for the network domain will appear in the area Group Or User Names of the dialog window Permissions For Spreadsheets. Mark the group Domain Admins and mark Full Control in the column Allow. This action will mark automatically the Change field. Select the button Apply.

- Стъпка 11. – Повторете процедура от предходните стъпки и добавете групата Domain Users към списъка Group Or User Names с потребители за ресурса. Задайте за тази група в колоната Allow само права за четене (Read). Затворете прозорците чрез натискане на бутоните Apply и OK.
4. Проверка достъпността на споделените ресурси
- Стъпка 1. – Изчакайте колегите си, които работят на друга виртуална машина, да стигнат то тази стъпка и се разменете с тях при достъпа до виртуалните машини. След като вече сте свързани към нова виртуална машина (Например, ако до сега сте работили на MAServer1 след размяната си с колегите, които са работили примерно на MAServer2, сега вие трябва да имате достъп до тази машина, а колегите ви до вашата). Влезте в ОС на виртуалния сървър посредством потребител MADomain.test\Student с парола MAPassword123.
Стъпка 2. – Стартирайте Windows PowerShell от стартовата лента и в появилия се прозорец въведете командата за стартиране на файлов браузър и преглед на споделената директория – explorer \\{ИМЕ НА СЪРВЪР}\Spreadsheets (заменете параметъра {Име на сървър} с името на компютъра, на който до сега сте работели). След изпълнението на командата ще се зареди файлов браузър, който ще ви представи директно съдържанието на споделената папка.
- Step 11. – Repeat the procedure from the previous steps and add the group Domain Users to the list Group Or User Names with users for the resource. Set for this group the column Allow only with read rights (Read). Close the windows using the clicking of the buttons Apply and OK.
4. Evaluation of the accessibility of the shared resources
- Step 1. – Wait for your colleagues, which work on the other virtual machines to reach this step of the lab. Change your place and login to a different virtual machine. For example if you were working on MAServer1 and your colleague is working on MAServer2, after the change you have to work on MAServer2 and he or she have to work on MAServer1. Login to the Operating System of the virtual server using username MADomain.test\Student and password MAPassword123.
Step 2. – Launch Windows PowerShell from the start bar and in the new window enter the command for launching the file explorer and view the shared directory – explorer \\{NAME OF THE SERVER}\Spreadsheets (change the parameter {NAME OF THE SERVER} with the name of the computer you’ve been working on). After the command implementation the file explorer will be loaded and it will directly shows you the content of the shared folder.


- Стъпка 3. – Изберете споделения файл и го отворете посредством WordPad. Модифицирайте съдържанието на файла и се опитайте да го запазите. Ще ви се изведе съобщение за грешка, което е породено от липсата на права на потребител Student за промяна на файла.
- Step 3. – Choose the shared file and open it by using WordPad. Modify the content of the file and try to save the file. A pop-up windows will appear with an error message. This is due to the lack of permission that the user Student is having.

- Стъпка 4. – Затворете WordPad и файла без да запазвате промените. Опитайте се да изтриете файла. Операцията също ще е неуспешна.
Стъпка 5. – Излезте и влезте обратно в ОС на сървъра, но този път използвайте потребител MADomain.test\Administrator с парола MAPassword123. Пробвайте отново да достъпите споделения файл и да промените неговото съдържание. Операцията успешна ли е? Запазете промените по файла!
5. Работа с NTFS права за достъп до споделени ресурси
- Стъпка 1. – Отново се разменете с колегите си и достъпете ОС на сървъра с администраторския профил за мрежовата област. Стартирайте файлов браузър и отворете дял C:\ където се намира папката Accounting. Изберете папката с десен бутон и от контекстното меню изберете Properties. На екрана ще се появи екрана с настройките за папката. Изберете таба Security.
Стъпка 2. – Натиснете бутона Edit. Ще се покаже нов диалогов прозорец за конфигуриране на правата за достъп до ресурса – Permissions For Accounting.
Стъпка 3. – Натиснете бутона Add. Ще се появи диалогов прозорец за избор на потребители, компютри или групи от потребители – Select Users, Computers, Service Accounts, or Groups. В полето Enter the object names to select въведете Student и натиснете бутона OK. Потребителят Student ще се появи в полето Group or user names на диалоговия прозорец Permissions for Accounting.
Стъпка 4. – Маркирайте потребителя Student и в полето за задаване на права за потребителя Permissions for Student изберете Allow Full Control, след което натиснете бутона OK за всички прозорци.
Стъпка 5. – Разменете се повторно с колегите си и стартирайте ОС на техния сървър с потребителския профил за мрежовата област Student с парола MAPassword123.
Стъпка 6. – Опитайте се повторно да промените съдържанието на създадения в предходните стъпки файл Budget. Успешен ли е опита? Ако сте направили всичко както трябва, би трябвало отново да нямате право да променяте съдържанието на файла.
Стъпка 7. – Върнете се обратно на своя сървър. Излезте и влезте обратно в системата, но този път използвайте профила Student за мрежовата област. Използвайте файлов браузър и отворете папката Accounting. Опитайте се да промените съдържанието на файла. Успешен ли е опита?
Стъпка 8. – Стандартните правила за споделяне на ресурси в рамките на корпоративна мрежа изискват достъп до ресурси да се осъществява на ниво файлова система, т.е. посредством NTFS права за достъп. Модифицирайте правата за NTFS достъп до папката Accounting, за да отговарят на настройките от следващата таблица.
- Step 4. – Close the WordPad and the file without saving the changes. Try to delete the file. This operation should be unsuccessful as well.
Step 5. – Logout and Login again in the OS of the Server, but this time use username MADomain.test\Administrator with password MAPassword123. Try again to access the shared file and to change its content. Is the operation successful this time? Save the changes to the file!
5. Working with NTFS access rights for shared resources
- Step 1. – Change your place with your colleague again and access the OS of the server with the network domain administrator profile. Launch file explorer and open partition C:\ where the Accounting folder is. Select the folder with the right mouse button and choose Properties. On the screen you will see a windows with folder properties. Select Security tab.
Step 2. – Select the Edit button. A new dialog window will appear that will help you with the configuration of the permissions for the resource – Permissions For Accounting.
Step 3. – Select the Add button. A dialog window will appear and you can select users, computers or group of users – Select Users, Computers, Service Accounts, or Groups. In the field Enter the object names to select enter Student and click OK. The user Student will appear in the Group or user names field of the dialog windows Permissions for Accounting.
Step 4. – Select the user Student and in the field of choosing permissions for that user – Permissions for Student select Allow Full Control, and then click the OK button of each window.
Step 5. – Change your place with your colleague again and login to the Operating System of his/her virtual machine. Use the user profile for the network domain, username Student with password MAPassword123.
Step 6. – Try again to change the content of the file that you have created in the previous steps Budget. Do you manage to change it?
Step 7. – Go back to your server again. Logout and login again to the system, but this time use the Student profile for the network domain. Use file explorer and open the Accounting folder. Try to change the content of the file. Did you manage to succeed?
Step 8. – The standard rules for sharing resources in enterprise networks require access to the resources to be managed on the file system level as well i.e. by using NTFS permissions. Modify the rules for the NTFS access to the folder Accounting, according to the table bellow.
| User/Group | Sharing permissions | NTFS file permissions |
|---|---|---|
| Student | Allow Full Control | Allow Modify Allow Read & Execute Allow List Folder Contents Allow Read Allow Write |
| Domain Users | Allow Full Control | Allow Read & Execute Allow List Folder Contents Allow Read |
| Domain Admins | Allow Full Control | Allow Full Control |
6. Споделяне на папки и файлове посредством Server Manager
!!ПОЗДРАВЛЕНИЯ!!
Вие успешно завършихте настоящото упражнение и преминахте през основните стъпки от процеса по споделяне и преглед на ресурси в рамките на една мрежова област.
- Стъпка 1. – Стартирайте Server Manager (на локалния сървър с профил за администратор на мрежовата област) и изберете Manage > Add Roles and Features. Ще се стартира помощника за добавяне на роли и компоненти – Add Roles and Features. Изберете бутона Next няколко пъти, докато не достигнете до страницата за избор на роли – Select server roles. От падащото меню за ролята File and Storage Services изберете отметката File and iSCSI Services. Продължете напред със стъпките на помощника за добавяне на роли и компоненти и не променяйте други настройки. Инсталирайте маркираната услуга.
Стъпка 2. – В основния екран на Server Manager ще се появят два нови елемента за раздела File and Storage Services. Изберете Shares, с което в основната част на екрана ще ви се заредят настройките за споделяне.
Стъпка 3. – От полето Shares изберете Tasks > New Share. На екрана ще се зареди помощника за създаване на нов споделен ресурс и ще се зареди неговата начална страница Select the profile for this share.
Стъпка 4. – От списъка File share profile, изберете SMB Share – Quick и натиснете бутона Next. Ще се зареди страницата Select the server and path for this share.
Стъпка 5. – В полето Share location изберете дял C:\ и продължете напред с бутон Next. Ще се зареди страницата Specify share name. В полето Share name въведете Documents и изберете Next. Ще се изведе страницата Configure share settings.
Стъпка 6. – Маркирайте полето Enable access-based enumeration и продължете напред с бутона Next. Ще се зареди страницата Specify permissions to control access.
Стъпка 7. – Изберете бутона Next и приложете настройките за достъп по подразбиране. Ще се зареди страницата Confirm selections. Изберете бутона Create. С тези действия автоматично ще се създаде споделен ресурс и информацията за него ще се изведе посредством страницата View results.
Стъпка 8. – Изберете бутона Close. Споделения ресурс ще се добави към полето Shares на Server Manager.
Вие успешно завършихте настоящото упражнение и преминахте през основните стъпки от процеса по споделяне и преглед на ресурси в рамките на една мрежова област.
6. Files and folder sharing using Server Manager
!!CONGRATULATIONS!!
You have successfully completed the exercise and now you know the basic steps of the process for sharing and overviewing the resources in the network domain.
- Step 1. – Start Server Manager (on the local server with the administrator profile of the network domain) and select Manage > Add Roles and Features. This will start the wizard for adding roles and features – Add Roles and Features. Select Next button several times until you reach the page for selecting roles – Select server roles. From the drop-down menu for the File and Storage Services feature make sure that the File and iSCSI Services is selected. Follow the wizard without changing anything else. Install the selected feature.
Step 2. – In the main screen of Server Manager two new components will appear in the File and Storage Services section. Select Shares, and in the main screen you will see the settings for sharing.
Step 3. – From the Shares section select Tasks > New Share. On the screen you will see the wizard for creating of new shared resources and its home page will appear: Select the profile for this share.
Step 4. – From the File share profile list, select SMB Share – Quick and click on the Next button. This will load the page: Select the server and path for this share.
Step 5. – In the Share location field select partition C:\ and proceed by clicking the Next button. This will load the page Specify share name. In the Share name field enter Documents and click the Next button. This will load the page: Configure share settings.
Step 6. – Select the field Enable access-based enumeration and proceed by clicking the Next button. This will load the page: Specify permissions to control access.
Step 7. – Click on the Next button and apply the setting for access by default. This will load the page Confirm selections. Select the Create button. The implementation of these step will automatically create the shared resource and the information about it will be displayed in the page View results.
Step 8. – Select the Close button. The shared resource will appear in the Shares section of the Server Manager.
You have successfully completed the exercise and now you know the basic steps of the process for sharing and overviewing the resources in the network domain.
