ONTAP Discussions

Add Windows Global Security group to CIFS SHARE access control

Kiko
1,403 Views

Hi!

Something strange is happening when I add a global security group to a share, or I don't understand what's going on.

I put in context: I create a Share and add a global security group to SHARE ACCESS CONTROL that contains a user and in turn, that security group is a member of the domain administrators group and domain users group.

From windows file explorer, I access the main NAS \\MyNas and see the shares that contains Folder-1, Folder-2 and Folder-3 as shares.

When I try to access any of the shared folders, the login window appears, I enter the credentials of the user who is in the security group that is the same as the one with which I started the session on the Windows PC and I do not access the content It keeps asking me to login.

If I remove the Share Access Control group from the shares and add the user. I can automatically access the content of the folders.

What could be happening?

 

The security of the SVM is by default, it accepts all types of negotiation protocols, without encryption and signing required.

 

Regards

2 REPLIES 2

Kiko
1,373 Views

Thanks Ontapforrum.

Thanks for all these links.

I have been reading many KBs for two days, including some of the ones you have indicated.

The funny thing is that if instead of adding a created security group to the share securrity, I add a predefined group of the type "domain users" or "Domain. Admins" and my user belongs to this group, I can access to share.

Thanks

Public