# Module 8: Remote Administration of Shared Folders

## Module 8: Remote Administration of Shared Folders

This module provides students with the knowledge and skills that are necessary to monitor and administer shared folders on local and remote computers. The module discusses how to use Computer Management to view a list of all shared folders on a computer and the users who have established active sessions on the computer.

1. Module 8: Remote Administration of Shared Folders Contents Overview 1 Introduction to Monitoring Shared Folders 2 Monitoring Access to Shared Folders on Remote Computers 3 Administering Shared Folders on Remote Computers 8 Lab A: Administering Shares on a Remote Computer 16 Review 24 This course is a prerelease course and is based on Microsoft Windows 2000 Beta 3 software. Content in the final release of the course may be different than the content included in this prerelease version. All labs in the course are to be completed using the Beta 3 version of Microsoft Windows 2000 Advanced Server.
3. Module 8: Remote Administration of Shared Folders iii Introduction Presentation: This module provides students with the knowledge and skills that are necessary 60 Minutes to monitor and administer shared folders on local and remote computers. The module discusses how to use Computer Management to view a list of all shared Lab: folders on a computer and the users who have established active sessions on 30 Minutes the computer. The module also explains how to share a folder on a remote computer and modify permissions for it. Finally, the module covers the procedures to send administrative messages to users and disconnect them from sessions and open files on a remote computer. There is one lab in this module. In it, students will access a share on a remote computer and modify its properties. Then, they will change the NTFS file system permissions on a shared folder, disconnect users from a shared folder, and share a folder on a remote computer. Materials and Preparation This section provides you with the materials and preparation needed to teach this module. Materials To teach this module, you need the following materials: !" Microsoft® PowerPoint® file 1556A_08.ppt !" Module 8, “Remote Administration of Shared Folders” Preparation To prepare for this module, you should: !" Read all the materials for this module. Some topics have animated slides that are indicated by an icon in the lower left corner of the slide. These slides require you to click them to play the animation. !" Review the Delivery Tips and Key Points for each section and topic. !" Complete the lab. !" Study the review questions and prepare alternative answers for discussion. !" Anticipate questions that students may ask. Write out the questions and provide answers to them.
4. iv Module 8: Remote Administration of Shared Folders Module Strategy Use the following strategy to present this module: !" Introduction to Monitoring Shared Folders Discuss the importance of monitoring shared resources on local and remote computers in order to maintain the security of the network. Explain how Microsoft Windows® 2000 provides the Computer Management tool for this task. Define the following terms: shares, sessions, and open files. !" Monitoring Access to Shared Folders on Remote Computers Demonstrate the procedure to connect to a remote computer by using the animated slide provided in the topic on connecting to a remote computer. Then demonstrate how to view information on shared folders, sessions, and open files on a remote computer. For each of these tasks, explain the information that is displayed. !" Administering Shared Folders on Remote Computers Discuss the procedures to share a folder on a remote computer and modify permissions to it. Then explain the need to send administrative messages to users after permissions to a shared folder are modified, and demonstrate the procedure to do so. Finally, introduce the reasons for disconnecting users from active sessions. Open files and walk students through the procedures to perform these tasks.
6. Module 8: Remote Administration of Shared Folders 1 Overview Slide Objective To provide an overview of the module topics and objectives. ! Introduction to Monitoring Shared Folders ! Monitoring Access to Shared Folders on Remote Lead-in In this module, you will learn Computers how to monitor and Administering Shared Folders on Remote Computers ! administer shared folders on remote computers. Network resources that multiple users use are typically installed in a central location. These locations are then shared, and individual users access the resources from the shares. A share is the term for a shared location such as a folder or root directory in a partition. As a system administrator, you need to monitor the usage of shares regularly to identify the shares that users access most often and to perform maintenance tasks. Also, to maintain the security of the network, you must be aware of every share that users access. This will ensure that only authorized users are accessing network resources. Microsoft® Windows® 2000 provides the ability to administer shared folders on both local and remote computers. A local computer is one at which you are present physically, and every other computer on the network is a remote computer. This means that a remote computer can be located next to your local computer or at the other end of the network. In this module, you will learn about the administrative tasks that you will perform on shared folders. At the end of this module, you will be able to: !" Monitor shared folders. !" Administer shared folders.
7. 2 Module 8: Remote Administration of Shared Folders Introduction to Monitoring Shared Folders Slide Objective ! Administer Shared Folders To introduce Computer on Local or Remote Computers Management. Lead-in Windows 2000 provides the Shared Folders Computer Management tool to administer shared folders Shares Log On on local and remote computers. Sessions ! Monitor and Administer Active Sessions Open Files Open ! Administer Open Files on a Share To monitor and administer shares on local and remote computers, Delivery Tip Windows 2000 provides Computer Management. You can use Computer Explain the following terms: shares, shared folders, Management to view information on shared folders and perform tasks such as sessions and open files. modifying permissions assigned to shared folders and determining the number of users accessing each shared folder. Open Computer Management and point out To access Computer Management, on the Start menu, point to Administrative the three subfolders under Tools, and then click Computer Management. In the Computer Management the Shared Folders folder. window that appears, expand System Tools. Notice the Shared Folders folder in the expanded items. Expand the Shared Folders folder to display the subfolders contained in it. Using the Shared Folders folder, you can view a summary of connections and resource use for local and remote computers. The Shared Folders folder contains three subfolders: Shares, Sessions, and Open Files. Using the Shares subfolder, you administer the shares on a local or remote computer. On shared folders you can perform tasks such as sharing an existing folder and setting permissions for a shared folder. Using the Sessions subfolder, you can administer user sessions. A session is defined as active when a user logs on to a computer from another computer. Computer Management provides the capability to view a list of all active sessions on a computer and the users who have activated those sessions. Using the Open Files subfolder, you can administer the files on shared folders that users open. You can identify the users accessing specific files at given times to determine whether all of them are authorized to do so.
8. Module 8: Remote Administration of Shared Folders 3 # Monitoring Access to Shared Folders on Remote Computers Slide Objective To introduce monitoring access to shared folders and open files on remote ! Connecting to a Remote Computer computers. ! Monitoring Shares on a Remote Computer Lead-in You can monitor shared ! Monitoring User Sessions on a Remote Computer folders and open files on remote computers. ! Monitoring Open Files on a Remote Computer You need to monitor shared folders to identify the number of users accessing Delivery Tip them. If a large number of users access the same folder, the rate at which This section explains using Computer Management to information can be accessed from the shared folder will decrease. To maintain monitor shared folders. an optimal rate of information access and prevent congestion, you must share Prepare students for the the information from another location as well. To do so, you need to create a topics by providing the copy of the shared information on another folder in a different computer and following key points of then share that folder. information. You can monitor the sessions that are activated when users establish connections to a remote computer. Also, you can monitor open files to determine which users are gaining access to the files in a shared folder and the identity of those users. Key Points You can monitor and administer any computer from a single location in the network. You can monitor shared folders, user sessions and open files on any computer to view information about the users accessing the computer.
9. 4 Module 8: Remote Administration of Shared Folders Connecting to a Remote Computer Slide Objective To explain how to connect to a remote computer. compmgmt - [Computer Management (Local)] Lead-in Action View Windows 2000 provides the compmgmt - [Computer Management (DENVER)] Computer Management (Local) Name capability to administer System Tools computers without your Storage Computer Management (DENVER) Connect to anothercomputer … Connect to another computer... Name having to be physically Server Applications and Services System Tools All Tasks System Tools located at them. Storage View Storage Server Applications and Services List… Export Server Applicatio Properties Help In a large network, the ability to administer computers without having to be Delivery Tip present at their physical locations simplifies administration greatly. With The slide for this topic is animated. The icon on the Windows 2000, you can administer computers and resources such as shared lower left corner indicates folders from a remote location. the animated slide. Use the To administer remote resources, you first need to connect to the remote slide to demonstrate the procedure to connect to a computer on which the resources are located. remote computer. To connect to a computer at a remote location: 1. In the Computer Management window, right-click Computer Management (Local) and then click Connect to another computer. 2. In the Select Computer dialog box, click the remote computer to which you need to connect, and then click OK. Notice that Computer Management (Local) now reads Computer Management (Remote computer name). This indicates that you can now perform tasks on the remote computer as if you were working on it locally.
10. Module 8: Remote Administration of Shared Folders 5 Monitoring Shares on a Remote Computer Slide Objective To explain monitoring shared folders on a remote compmgmt - [Computer Management (DENVER)\System Tools\Shared Folders\Shares] computer. Action View Computer Management (DENVER) Shared Folder Shared Path Type # Cli Lead-in System Tools ADMIN$D:\WINNT Windows 0 Windows 2000 provides Performance Logs and Alerts Local Users and Groups C$ C:\ Windows 0 an administrative tool to System Information D$IPC$ D:\ Windows Windows 0 3 monitor shared folders on Services Shared Folders NETLOGON D:\WINNT\SYSVOL\sysvol\… Windows 0 a remote computer. Shares print$D:\WINNT\System32\spool\… Windows 0 Public C:\Public Windows 2 Sessions Open Files SYSVOL D:\WINNT\SYSVOL\sysvol Windows 0 Event Viewer Device Manager Storage Server Applications and Service As the administrator, you have the ability to view all shares on the network, Delivery Tip including hidden shares. This helps you monitor all the shares on the network Open the Shares folder in Computer Management to ensure network security. Also, monitoring the shares helps you to determine when you discuss each item whether any share on a server is being accessed by a large number of users. If in the table. it is, you must take appropriate action to reduce the load on the server. To view information about remote shared folders: 1. Connect to the remote computer on which the remote shared folder is located. 2. In the Computer Management window, expand System Tools, expand Shared Folders, and then click Shares. The details pane displays information on all shares. The following table describes the information available on the shared folders. Column name Description Shared Folder The name given to the folder when it was shared. Shared Path The path to the shared folder. Type The type of network connection used to access the remote computer, either Windows, NetWare or Macintosh. # Client The number of users who have made connections to the shared Redirections folder. Comment Comment about the folder provided when the folder was shared. Note Windows 2000 does not update the list of shares, open files, and user sessions automatically. To update these lists, on the Action menu, click Refresh. 11. 6 Module 8: Remote Administration of Shared Folders Monitoring User Sessions on a Remote Computer Slide Objective To explain how to monitor compmgmt - [Computer Management (DENVER)\System Tools\Shared Folders\Sessions] user sessions on a remote Action View computer. Computer Management (DENVER) User Computer Type Open Files Connected ... Idle Lead-in System Tools Performance Logs and Alerts Judyl LONDON Windows 2 12:05:27 AM 12:0 Use the Sessions folder in Local Users and Groups Computer Management to System Information Services view user sessions on a Shared Folders remote computer. Shares Sessions Sessions Open Files Event Viewer Device Manager Storage Server Applications and Services You can view a list of users who have current network connections to a remote Delivery Tip computer and the files to which they have connections. The Sessions folder in Open the Sessions folder in Computer Management Computer Management displays this information. A single session will exist for when you discuss each item each user connected to a computer regardless of how many shares or files are in the table. being accessed. You can use this information to determine which users you should contact when you need to shut down the server from which the users are accessing files. The following table describes the information that is available in the Sessions folder. Column name Description User The user with a current network connection to the computer. Computer The computer name of the user’s computer. Type The type of network connection used to access the remote computer: Windows, NetWare, or Macintosh. Open Files The number of files that the user has open on the computer. Connected Time The time in hours and minutes that has elapsed since the user established the current session. Idle Time The time that has elapsed since the user last initiated an action. Guest Whether the user connected to the computer using the built-in Guest account. 12. Module 8: Remote Administration of Shared Folders 7 Monitoring Open Files on a Remote Computer Slide Objective To explain monitoring access to open files on a compmgmt - [Computer Management (DENVER)\System Tools\Shared Folders\Open Files] remote computer. Action View Computer Management (DENVER) Open File Accessed By Type # Locks Open Mode Lead-in System Tools Status.doc Judyl Windows 0 Read You can monitor the status Performance Logs and Alerts Local Users and Groups \PIPE\srvsvc Administrator Windows 0 Write+Read of all files that are opened System Information by users on a remote Services Shared Folders computer. Shares Sessions Open Files Files Event Viewer Device Manager Storage Server Applications and Service A shared folder may have a large number of files that are accessed by multiple Delivery Tip users. As an administrator, it is important for you to know which files within a Open the Open Files folder in Computer Management shared folder are accessed most often and the identity of the users accessing when you discuss each item those files. To access information about the users who have opened connections in the table. to each file in a shared folder, you use the Open Files folder in Computer Management. To access information about remote open files: 1. Connect to the remote computer on which the open file is located. 2. Click System Tools, click Shared Folders, and then click Open Files. The details pane displays information on all open files. The following table describes the information available on the open files. Column name Description Open File The name of the open file being accessed. Accessed By The logon name of the user who has the file open. Type The type of network connection used to access the remote computer: Windows, NetWare, or Macintosh. # Locks The number of locks on the file. Applications can request that the operating system lock a file in order to gain exclusive access and prevent other programs from making changes to the file. Open Mode The type of access, such as Read or Write, that the user’s application was granted when the file was opened. 13. 8 Module 8: Remote Administration of Shared Folders # Administering Shared Folders on Remote Computers Slide Objective To explain the tasks involved in administering remote shares. ! Sharing a Folder on a Remote Computer Lead-in ! Modifying Permissions for a Shared Folder on a Remote In this section, you will learn Computer how to share folders and change permissions to ! Sending Administrative Messages to Users shared folders as per administrative needs. ! Disconnecting User Sessions on a Remote Computer ! Disconnecting Users from Open Files on a Remote Computer To provide a location from which multiple users can access information that is Delivery Tip common to everyone, you can put the information in an existing folder and This section explains using Computer Management to share it or create a new folder, put the information in it, and then share it. monitor shared folders. After you create shared folders on a computer, you need to administer them to Prepare students for the ensure that they are being used optimally. The task of administering shared topics by providing the following key points folders includes creating the shared folders, limiting the number of users who information. can connect to the shared folders, modifying permissions to the shared folders, and stopping the folders from being shared when they are no longer required. If you need to take away users’ access rights to a, you can send an e-mail Key Points message to the users and then disconnect them from an open file or end a You can share an existing folder or create a new folder session. and share it. With Windows 2000, you can perform all these administrative tasks for shared folders on both a local and a remote computer. However, you must have the You can modify the default permissions assigned to a appropriate rights to do so. To administer a computer running Windows 2000 shared folder. Professional, you must be a member of the Administrators Domain Local group or the Power Users group. To administer a Windows 2000 Server, you must be After modifying permissions, a member of the Administrators Domain Local group or the Server Operators you can send messages to group. users on the network and then disconnect open files and sessions. 14. Module 8: Remote Administration of Shared Folders 9 Sharing a Folder on a Remote Computer Slide Objective compmgmt - [Computer Management (DENVER)\System Tools\Shared Folders\Shares] Action View To explain how to share a folder on a remote Computer Management (Local) Shared Folder System Tools Shared Path Type # Client Redirec.. access C:\deploy\access Windows 0 computer. Performance Logs and... ADMIN$ C:\WINNT.1 Windows 0 Local Users and Groups Lead-in C$System Information Create Shared Folder Wizard deploy C:\ C:\deploy Windows 0 Windows 3 You can share existing Services Shared Folders Name the Shared Folder and Control Computer Access excel C:\deploy\excel Windows 0 You can control use of the shared folder by naming it appropriately and limiting the folders or create new folders Shares IPC$ operating systems that have access to it. Windows 0 NETLOGON C:\WINNT.1\SYSVOL… Windows 2 to share on a remote Sessions You will share package folder: the following c:\package Windows 0 Open Files \\DENVER\C\$\REPORTS computer. Event Viewer SYSVOL C:\WINNT.1\SYSVOL… Device Manager Type a sharedtemp name thatC:\temp folder will be seen by network users. Storage Name: User Folders C:\User Folders Reports Server Applications and ... word C:\deploy\word Type a a description for the shared folder (optional). Description: Computers running the following operating systems have access to the shared folder: Microsoft Windows Novell NetWare Apple Macintosh < Back Next > Cancel You can use Computer Management to share a folder on a remote computer. Delivery Tip When you use this method, the Full Control shared folder permission is Demonstrate the procedure to share a folder on a automatically assigned to the Everyone group. remote computer. To share a folder: 1. Connect to the remote computer on which the folder to be shared is located. 2. In the Computer Management window, click Shared Folders, right-click Shares, and then on the Shares menu, click New File Share. 3. In the Create Shared Folder wizard, click the name of the folder (if you need to share an existing folder) or specify a name to create a new folder to share, and then click Next. Now you need to set permissions to limit access to the shared folder. 4. To change permissions, select one of the three options that the following table describes, and then click Next. Option Description Keep the current permissions Inherited permissions from the parent folder are retained. Only I have full control, but others The owner is given the Full Control can read files in this folder permission. The Everyone group is given Read Only access. Everyone has access and full control The Everyone group is given Full Control. • To allow permissions inheritance, select the Apply these permissions to all folders and files in this folder check box. • To prevent permissions inheritance, clear the Apply these permissions to all folders and files in this folder check box.
15. 10 Module 8: Remote Administration of Shared Folders 5. Accept the default name for the shared folder, or type a different name and then click Next. Optionally, you can type a description for the shared folder. 6. To finish creating the shared folder, click Finish. If you do not need a folder to be shared any more, you can stop sharing it. To stop sharing a folder: !" Right-click the shared folder, and then click Stop Sharing. Important If you stop sharing a folder while a user has a file open, the user may lose data.
16. Module 8: Remote Administration of Shared Folders 11 Modifying Permissions for a Shared Folder on a Remote Computer public Properties Slide Objective General Share Permissions Security To explain how to modify the default permissions of a public Properties share on a remote Share Name: public General Share Permissions Security computer. Path: D:\public Name Lead-in Comment: Everyone Add... You can modify the default User Limit: Remove permissions assigned to a Maximum Allowed shared folder on a remote Allow 10 Users computer. Permission Allow Deny Caching... Full Control Change Read OK Cancel Apply OK Cancel Apply When you share a folder, Windows 2000 assigns some settings to it by default. Delivery Tip However, you can modify these settings to accommodate the needs of your Demonstrate the procedures to set share permissions network. For example, you can limit the number of users who access a shared and NTFS permissions. folder. This will help you to stay in compliance with licensing restrictions for shared applications in the shared folder. Many applications limit the number of users who can access the application at any one time. You must observe this restriction and specify the number of users accordingly. Key Point It is a good practice to use the default share Note On computers running Windows 2000 Professional, a maximum of permissions and modify the only 10 users can connect to the computer at any one time. NTFS permissions as required. In addition, if a shared folder is being accessed by a large number of users, the access rate will be slow, and computer performance will suffer on slower systems. To avoid such a situation, you can share the information out on folders on other computers and limit the access to each shared folder. You can also modify share permissions and permissions for the NTFS file system that are assigned to the shared folder by default. When a folder is shared, the Full Control share permission is assigned to the Everyone group. You can modify this assignment by assigning permissions to specific users and groups only. However, as a good practice, use the default share permissions and modify only NTFS permissions. To limit access to a shared folder on a remote computer: 1. Connect to the remote computer on which the shared folder is located. 2. In the Computer Management window, right-click the shared folder, and then click Properties. 3. In the Properties dialog box for the shared folder, on the General tab, select the Allow Users option, enter the number of users who can access the shared folder at any one time, and then click OK.
17. 12 Module 8: Remote Administration of Shared Folders To modify share permissions for a shared folder on a remote computer: 1. In the Properties dialog box for the remote share, click the Share Permissions tab. 2. Specify which of the share permissions—Full Control, Change, or Read— you need to allow or deny to each user by selecting the appropriate check boxes. Note You can modify NTFS permissions only for shared folders on NTFS partitions. To modify NTFS permissions for a shared folder on a remote computer: 1. In the Properties dialog box for the remote share, click the Security tab. 2. Specify which of the NTFS permissions that you need to allow or deny to each user by selecting the appropriate check boxes. Note Permissions on shared folders are not effective until a user accesses the shared folder over the network.
18. Module 8: Remote Administration of Shared Folders 13 Sending Administrative Messages to Users Slide Objective To describe how to send administrative messages to users and the reasons for Send Console Message doing so. Message: Lead-in This server will shut down in 5 minutes for maintenance. Please save all work in progress and then disconnect. You may lose Send You can send administrative data if your files are open when the server is shut down. Cancel messages to users and computers. Recipients: DENVER Add... VANCOUVER NORTHAMERICA Remove You can send administrative messages to one or more users or computers. Delivery Tip If there is going to be a disruption to a computer on which network resources Provide a scenario when administrative messages are shared, you should send administrative messages to users with current are sent to users. For connections to the computer. Some common reasons for sending administrative example, before messages are to notify users when you intend to: disconnecting open files and sessions to change !" Perform a backup or restore operation. permissions to a shared !" Disconnect users from a resource. folder, you send a message to inform users about the !" Upgrade software or hardware. event. !" Shut down the computer. To send an administrative message to users accessing a remote computer: 1. In the Computer Management window, on the Action menu, click Send Console Message. 2. In the Send Console Message dialog box, type the message that you want to send. By default, all currently connected computers appear in the list of recipients to which you can send a message. You can add other users or computers to this list by using the Add button, and you can remove users and computers from the list by using the Remove button. 3. Click Send. Using this method, you can send messages only to those users who are connected to a remote computer. To send a message to all users on the network, use the net send command. To send a message to all users on the network: • At a command prompt, type net send /domain:domain_name message This command is useful in large network environments where administrative messages about the status of servers must be sent to all users on the network.
19. 14 Module 8: Remote Administration of Shared Folders Disconnecting User Sessions on a Remote Computer Slide Objective To describe how to compmgmt - [Computer Management (DENVER)\System Tools\Shared Folders\Sessions] disconnect users from Action View sessions on a remote Computer Management (DENVER) User Computer Type Open Files Connected ... Idle computer and to explain the System Tools Judyl LONDON Windows 2 12:05:27 AM 12:0 reasons for doing so. Performance Logs and Alerts Close Open File Close Session Local Users and Groups Lead-in System Information Services All Tasks You can disconnect users Shared Folders Refresh who have network Shares Help Sessions Sessions connections to a remote Open Files computer. Event Viewer Device Manager Storage Server Applications and Services You can disconnect one or all users with network connections to a remote Delivery Tip computer. Disconnect users when you want to: Provide a scenario when user sessions are !" Have changes to shared folder permissions and NTFS permissions on a disconnected. For example, remote computer take effect immediately. A user retains all permissions for to help multiple users a shared resource that were assigned when the user connected to the access a server with limited licenses, you should monitor resource. These permissions are evaluated again the next time that a user all sessions and close idle makes a connection. sessions. !" Free idle connections on a remote computer so that other users can make connections if the maximum number of connections has been reached. Important After you disconnect a user, the user can immediately make a new connection. If the user gains access to a shared folder from a Windows-based client computer, the client computer will automatically reestablish the connection with the shared folder. It will do so without user intervention unless you change the permissions to prevent the user from gaining access to the shared folder or you stop sharing the folder to prevent any user from gaining access to the shared folder. To disconnect a single user from a shared file on a remote computer, connect to the remote computer, and, in the Sessions folder in the Computer Management window, right-click the user name and click Close Session. To disconnect all users from a specific share, right-click the Sessions folder, and then click Disconnect All Sessions. Caution To prevent data loss, always notify users when a computer on which network resources are shared will be out of service. Additionally, make sure that no users are in the process of gaining access to shared folders or files when you stop sharing a folder or shut down the computer.

