Network share: enable enumeration based on access EBA

Introduction

The access-based enumeration allows to display in a network share, only folders and files whose use has at least a right of reading. Other documents and folders will be hidden.

Enabling this feature will increase the CPU resource consumption on the file server because at each access this will check what should be displayed.

In order to work properly, the NTFS rights must be set correctly and requires disabling the inheritance and removing the SERVER \ Users group rights because this group contains the Domain Users group.

Enable enumeration based on access EBA

1. On the server where the share is located, launch Server Manager and go to Manage File and Storage Services and view Shares 1 .
Server manager

2. Right click on the shared folder 1 where the EBA must be activated and click Properties 2 .
Shared folder

3. Check the Enable access-based enumeration 1 check box and click Apply 2 then OK 3 .
Active EBA

The EBA is now enabled on the shared folder, we will see now configure the rights.

Configure NTFS rights to use EBA

To illustrate the tutorial, in the IT folder, I created a folder pmartin where only the user pmartin has the rights to it.
Folder example

On a post, I logged in with the user dbon and I went on sharing, as can be seen on the screenshot below, the pmartin folder is not displayed.
the folder is not displayed

Conclusion

Access-based enumeration provides additional security by hiding folders that users do not have access to, to work properly this involves properly configuring NTFS rights.



Related Posts


QNAP: add a shared folder

In this tutorial, we will see how to create a shared folder with a QNAP NAS and access it from Windows. Creating the shared folder 1. Go to the administration interface and open Control Panel <<

GPO: User Folder Redirection

Presentation User Folder Redirection allows Windows to store the contents of certain user profile folders on a network location. This solution has the following advantages: No local file storage.Possi

File Server Resource Manager – FSRM – Files Filter

File Server Resource Manager Overview In this tutorial, I will introduce the File Server Resource Manager FSRM, which is a feature of the File Server role. FSRM allows several things at the file serve