<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NetApp Share ACL vs. DACL in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127761#M22944</link>
    <description>&lt;P&gt;Wow that was dumb of me. Sorry I was way trying to overcomplicate this and didn't think about what these actually were. Sorry about that. Thanks for head check, I need it every now and then. I'm new to netapp so I just straight up tried to be overcomplex.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Feb 2017 18:19:24 GMT</pubDate>
    <dc:creator>JV-CA</dc:creator>
    <dc:date>2017-02-03T18:19:24Z</dc:date>
    <item>
      <title>NetApp Share ACL vs. DACL</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127750#M22937</link>
      <description>&lt;P&gt;Is there a way to sync the ACL on the NetApp shares to sync back to windows? The permissions are set correctly on the ACL and only those on the ACL have access to them but of course the DACL shows everyone on the windows side. This is obviously more asthetic than anything but if an audit happened it's just one more thing I would have to explain/prove.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 15:29:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127750#M22937</guid>
      <dc:creator>JV-CA</dc:creator>
      <dc:date>2025-06-04T15:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: NetApp Share ACL vs. DACL</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127752#M22938</link>
      <description>&lt;P&gt;I'm not sure what you are saying here. Are you talking Netapp share permission?&lt;BR /&gt;&lt;BR /&gt;Can you give us a deeper example&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 16:58:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127752#M22938</guid>
      <dc:creator>JGPSHNTAP</dc:creator>
      <dc:date>2017-02-03T16:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: NetApp Share ACL vs. DACL</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127755#M22939</link>
      <description>&lt;P&gt;Sure thing, if you look at the output below, the vserver cifs share command shows the share level permission on NetApp, so only Domain Admins have access. When you look at the vserver security output, it shows the Windows DACL which still has Everyone listed, so if I go into the properties in Windows it will look like Everyone has access. Like I said though this is really asthetic or so I wouldn't have to explain this for an audit or anything as the permissions work the way they should on the NetApp. Is there a way to have the permissions on NetApp propogate so they are in sync on the Windows DACL as well?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SAN::&amp;gt; vserver cifs share access-control show -share Test&lt;BR /&gt;Share User/Group User/Group Access&lt;BR /&gt;Vserver Name Name Type Permission&lt;BR /&gt;-------------- ----------- --------------------------- ----------- -----------&lt;BR /&gt;svm01 Test Domain Admins windows Full_Control&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SAN::&amp;gt; vserver security file-directory show -vserver svm01 -path /Test&lt;/P&gt;&lt;P&gt;Vserver: svm01&lt;BR /&gt;File Path: /Test&lt;BR /&gt;File Inode Number: 64&lt;BR /&gt;Security Style: ntfs&lt;BR /&gt;Effective Style: ntfs&lt;BR /&gt;DOS Attributes: 10&lt;BR /&gt;DOS Attributes in Text: ----D---&lt;BR /&gt;Expanded Dos Attributes: -&lt;BR /&gt;UNIX User Id: 0&lt;BR /&gt;UNIX Group Id: 0&lt;BR /&gt;UNIX Mode Bits: 777&lt;BR /&gt;UNIX Mode Bits in Text: rwxrwxrwx&lt;BR /&gt;ACLs: NTFS Security Descriptor&lt;BR /&gt;Control:0x8004&lt;BR /&gt;Owner:BUILTIN\Administrators&lt;BR /&gt;Group:BUILTIN\Administrators&lt;BR /&gt;DACL - ACEs&lt;BR /&gt;ALLOW-Everyone-0x1f01ff&lt;BR /&gt;ALLOW-Everyone-0x10000000-OI|CI|IO&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 17:35:00 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127755#M22939</guid>
      <dc:creator>JV-CA</dc:creator>
      <dc:date>2017-02-03T17:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: NetApp Share ACL vs. DACL</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127758#M22941</link>
      <description>&lt;P&gt;You are displaying two different things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are displaying share level permissions vs ntfs file level permissions. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 17:49:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127758#M22941</guid>
      <dc:creator>JGPSHNTAP</dc:creator>
      <dc:date>2017-02-03T17:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: NetApp Share ACL vs. DACL</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127759#M22942</link>
      <description>&lt;P&gt;Yes I understand that, the NTFS permissions don't really matter as the share permissions on the netapp are working correctly. I know I could go into the NTFS permission on windows and change them manually I was just wondering if there's a way to push the permissions from the share to match in NTFS since they are both windows groups. Everything I have seen online has pointed to manually changing them in windows.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 17:57:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127759#M22942</guid>
      <dc:creator>JV-CA</dc:creator>
      <dc:date>2017-02-03T17:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: NetApp Share ACL vs. DACL</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127760#M22943</link>
      <description>&lt;P&gt;Those are two separate entire entities. &amp;nbsp;It's basic windows, two constructs, Share ACLs' and File System ACLs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you create a file system, the default permissions are everyone/full control. &amp;nbsp;I don't think that's modifiable. &amp;nbsp;Same with shares, you need to go edit them and create access lists.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the standard practice in the industry is either&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;share level - everyone / full control or authenticated users - full control&lt;/P&gt;&lt;P&gt;ntfs - this is where you lock the files down with security groups etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no concept of pushing down permissions from a share to a file system. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a good read -&amp;nbsp;&lt;A href="https://blog.varonis.com/the-difference-between-share-and-ntfs-permissions/" target="_blank"&gt;https://blog.varonis.com/the-difference-between-share-and-ntfs-permissions/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 18:06:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127760#M22943</guid>
      <dc:creator>JGPSHNTAP</dc:creator>
      <dc:date>2017-02-03T18:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: NetApp Share ACL vs. DACL</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127761#M22944</link>
      <description>&lt;P&gt;Wow that was dumb of me. Sorry I was way trying to overcomplicate this and didn't think about what these actually were. Sorry about that. Thanks for head check, I need it every now and then. I'm new to netapp so I just straight up tried to be overcomplex.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 18:19:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/127761#M22944</guid>
      <dc:creator>JV-CA</dc:creator>
      <dc:date>2017-02-03T18:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: NetApp Share ACL vs. DACL</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/128232#M23019</link>
      <description>&lt;P&gt;If you want to set NTFS permissions on files or folders from storage you can use fsecurity,&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2017 21:02:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/NetApp-Share-ACL-vs-DACL/m-p/128232#M23019</guid>
      <dc:creator>Suryaprathap</dc:creator>
      <dc:date>2017-02-17T21:02:21Z</dc:date>
    </item>
  </channel>
</rss>

