- Joined
- Jan 14, 2023
- Messages
- 623
Hello all,
I recently discovered that it is possible to run executables on my mapped network drives from our windows machines. For security purposes I don't want to allow that.
I went into the share settings and under advanced I chose all permissions except for execute:
However then I am not able to access the mount anymore:
switching back to basic (modify) resolves the issue.
The account from which I am logged in to the share also has Full Control, I assume this is inherited from the owner flag, since I created that folder:
What would be the best way to revoke execution rights for me and other users? There are two users overall using Win 11 and Win 8 (Win 10 in the near future, when I get around to the update).
I'm trying to advance our security by being conscious to settings like that, I also created a separate admin account under windows when I switched to win 11 and gave myself a standard user account. I want to follow the same practice for the win 8 machine.
Thanks in advance!
OS Version:TrueNAS-SCALE-22.12.3.3
Product:B560M-ITX/ac
Model:Intel(R) Core(TM) i3-10100 CPU @ 3.60GHz
Memory:62 GiB
I recently discovered that it is possible to run executables on my mapped network drives from our windows machines. For security purposes I don't want to allow that.
I went into the share settings and under advanced I chose all permissions except for execute:
However then I am not able to access the mount anymore:
switching back to basic (modify) resolves the issue.
The account from which I am logged in to the share also has Full Control, I assume this is inherited from the owner flag, since I created that folder:
What would be the best way to revoke execution rights for me and other users? There are two users overall using Win 11 and Win 8 (Win 10 in the near future, when I get around to the update).
I'm trying to advance our security by being conscious to settings like that, I also created a separate admin account under windows when I switched to win 11 and gave myself a standard user account. I want to follow the same practice for the win 8 machine.
Thanks in advance!