Can not get access files from Windows 7 to Claims-based file authorization share


we have ad level 2012r2, dcs running 2012r2 of course, , have clustered file server (3 fsnodes running 2012r2).

we enabled 2 policies 

kdc support claim

kerberos support claim

we created 1 claim type in adac (for example "division" source property). filled property ad accounts our value "it"

on fs made share folder itdivision:

- set permissions  domain users can modify if user.division equals "it"

so on windows 8 users can access files on share , on windows 7 cant =\ . know many presentations dynamic access control file server must enroll user claims if client not support claims (service-for-user-to-self) . 




hi,

>>so on windows 8 users can access files on share , on windows 7 cant =\ . know many presentations dynamic access control file server must enroll user claims if client not support claims (service-for-user-to-self) . 

how going? was there error message? far know, dynamic access control (dac) should work downlevel clients. it’s backwards compatible. florain explains in following blog:

for non-windows 8 , non-windows server 2012 boxes accessing dac-protected file shares, users not carry claims. them, server 2012-based file share query active directory , proxy claims request figure out claims user , machine bring. file server checks in name of user, whether should have claims. information, file server evaluates access file share. yeah – dac works downlevel clients, too. it’s backwards compatible. , totally transparent windows 7.

questions regarding dynamic access control (faq)

http://www.frickelsoft.net/blog/?p=293

in addition, regarding dynamic access control, following blog can referred more information.

dynamic access control in windows server 2012

http://www.infoq.com/news/2012/10/dynamic-access-control

please note: since above 2 website are not hosted microsoft, link may change without notice. microsoft not guarantee accuracy of information.

best regards,

frank shen




Windows Server  >  File Services and Storage



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client