<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Netapp CIFS share not accessible by domain users whereas accessible by domain admins in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-CIFS-share-not-accessible-by-domain-users-whereas-accessible-by-domain/m-p/125172#M26976</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have netapp cluster mode in the environment and I have an issue with CIFS shares, most of users who are domain admins. they are able to access the cifs share folders but the domain users are not able to access the folder. can anyone help me out if i need to do any settings to fix the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;VK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 18:21:15 GMT</pubDate>
    <dc:creator>1VINAYKUMAR</dc:creator>
    <dc:date>2025-06-04T18:21:15Z</dc:date>
    <item>
      <title>Netapp CIFS share not accessible by domain users whereas accessible by domain admins</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-CIFS-share-not-accessible-by-domain-users-whereas-accessible-by-domain/m-p/125172#M26976</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have netapp cluster mode in the environment and I have an issue with CIFS shares, most of users who are domain admins. they are able to access the cifs share folders but the domain users are not able to access the folder. can anyone help me out if i need to do any settings to fix the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;VK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 18:21:15 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-CIFS-share-not-accessible-by-domain-users-whereas-accessible-by-domain/m-p/125172#M26976</guid>
      <dc:creator>1VINAYKUMAR</dc:creator>
      <dc:date>2025-06-04T18:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Netapp CIFS share not accessible by domain users whereas accessible by domain admins</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-CIFS-share-not-accessible-by-domain-users-whereas-accessible-by-domain/m-p/125175#M26977</link>
      <description>&lt;P&gt;There are two important factors for CIFS shares, the Share ACL and the NTFS permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So let's start with both&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the share ACL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And what are the NTFS permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, why are people domain administrators? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 18:48:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-CIFS-share-not-accessible-by-domain-users-whereas-accessible-by-domain/m-p/125175#M26977</guid>
      <dc:creator>JGPSHNTAP</dc:creator>
      <dc:date>2016-11-07T18:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Netapp CIFS share not accessible by domain users whereas accessible by domain admins</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-CIFS-share-not-accessible-by-domain-users-whereas-accessible-by-domain/m-p/125186#M26978</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You haven't provided enough information to help identify the cause of the issue for troubleshooting. Can you please share the results of the following commands?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;cluster1::&amp;gt; vserver cifs share show -vserver vserver1 -share-name volume1$ -fields acl
vserver  share-name  acl
-------- ----------- -----------------------------------------------------------
vserver1 volume1$ "BUILTIN\Administrators / Full Control","Everyone / Change"&lt;BR /&gt;&lt;BR /&gt;cluster1::&amp;gt; qtree show -vserver vserver1&lt;BR /&gt;Vserver&amp;nbsp;&amp;nbsp;&amp;nbsp; Volume&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Qtree&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Style&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oplocks&amp;nbsp;&amp;nbsp; Status&lt;BR /&gt;---------- ------------- ------------ ------------ --------- --------&lt;BR /&gt;vserver1&amp;nbsp;&amp;nbsp; volume1&amp;nbsp;&amp;nbsp;&amp;nbsp; ""&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ntfs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enable&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&lt;BR /&gt;vserver1&amp;nbsp;&amp;nbsp; volume1&amp;nbsp;&amp;nbsp;&amp;nbsp; qtree1&amp;nbsp;&amp;nbsp;&amp;nbsp; ntfs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enable&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&lt;BR /&gt;&lt;BR /&gt;cluster1::&amp;gt; local-group show-members -vserver vserver1 -group-name "BUILTIN\Administrators"&lt;BR /&gt;&lt;BR /&gt;Vserver&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Members&lt;BR /&gt;-------------- ---------------------------- ------------------------&lt;BR /&gt;vserver1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; BUILTIN\Administrators&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VSERVER1\Administrator&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CONTOSO\Vserver Admins&lt;BR /&gt;&lt;BR /&gt;C:\&amp;gt;icacls \\vserver1\volume1$&lt;BR /&gt;\\vserver1\volume1$ BUILTIN\Administrators:(OI)(CI)(F)&lt;BR /&gt;\\vserver1\volume1$ CONTOSO\Data Admins:(OI)(CI)(F)&lt;BR /&gt;&lt;BR /&gt;Successfully processed 1 files; Failed processing 0 files&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: The default AD group "Domain Admins" should not be used to managed access to data on your CIFS vservers. See the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://technet.microsoft.com/en-us/windows-server-docs/identity/ad-ds/plan/security-best-practices/appendix-f--securing-domain-admins-groups-in-active-directory" target="_blank"&gt;https://technet.microsoft.com/en-us/windows-server-docs/identity/ad-ds/plan/security-best-practices/appendix-f--securing-domain-admins-groups-in-active-directory&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;"Domain Admins are, by default, members of the local Administrators groups on all member servers and workstations in their respective domains"&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you perform a CIFS setup on a vserver it becomes a "member server" within the domain which you join it to and by default the domain admins group are automatically added as members of the local administrators group on the vserver. Just because this is the default setting, it does NOT mean you should leave it that way. For example, the default permissions when you create an NTFS volume are "Everyone\Full Control". This is to ensure you have access to connect to the volume in order to secure the NTFS permissions and delegate administrative access to your data (during that process you should remove remove "Everyone\Full Control" and delegate administrative access to your data to an AD group)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So once you have joined the domain I recommend you delegate administrative access to your vservers, EG create a "Vserver Admins" AD group explicilty for the purpose of delegating administrative control of your vservers and add that group to the local Administrators group on your vservers then remove the "Domain Admins" group. EG:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;cluster1::&amp;gt; local-group add-members -vserver vserver1 -group-name "BUILTIN\Administrators" -member-names "CONTOSO\Vserver Admins"

cluster1::&amp;gt; local-group remove-members -vserver vserver1 -group-name "BUILTIN\Administrators" -member-names "CONTOSO\Domain Admins"&lt;/PRE&gt;&lt;P&gt;The "Domain Admins" group is for Active Directory administration, it should NOT be used for data administration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Matt&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 02:55:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-CIFS-share-not-accessible-by-domain-users-whereas-accessible-by-domain/m-p/125186#M26978</guid>
      <dc:creator>mbeattie</dc:creator>
      <dc:date>2016-11-08T02:55:47Z</dc:date>
    </item>
  </channel>
</rss>

