> For the complete documentation index, see [llms.txt](https://ghoulsec.gitbook.io/ghoulsec-vault/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ghoulsec.gitbook.io/ghoulsec-vault/server-are-fun/servers/windows-sever/ad-fileserver.md).

# AD FileServer

An **Active Directory File Server** is a server that uses **Windows Server** and is integrated with **Active Directory (AD)** to manage and share files across a network. It uses **AD** for user authentication and permission management, ensuring that only authorized users can access files and folders.

#### Key Features:

1. **Centralized File Storage**: File servers store and manage data centrally, making it easier for users to access and share files within the network.
2. **Access Control**: File access and permissions are managed through **Active Directory**. Administrators can set permissions for files or directories based on user or group membership, ensuring security and controlled access.
3. **Sharing and Collaboration**: AD File Servers make it easier for users to collaborate by enabling file sharing with specific users or groups, while keeping track of who has access to what data.
4. **Integration with AD**: Since the file server is integrated with AD, it can leverage AD for **authentication** (validating users) and **authorization** (determining what actions a user can take on files/folders).

We will now setup the AD file share to enable the AD file server :&#x20;

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2Fo1nWHVTRGLvNHjQxZCYM%2Fimage.png?alt=media&amp;token=b0a32b6b-acf7-41a3-a7a3-beaeb3ea0c83" alt=""><figcaption></figcaption></figure>

Now we will setup the disk resource pool for the file server under the server manager

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2F1urSrPFrkpyAgRomgLsC%2Fimage.png?alt=media&amp;token=0908201c-60dd-4f64-b032-a97d67758781" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2Fk5Z0X9WgqWafwCcdTdJU%2Fimage.png?alt=media&amp;token=b2ff199b-6260-42f7-b3d0-47253a80d9cc" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FhP1T4JFpJ3N43QYphBTj%2Fimage.png?alt=media&amp;token=7008a8ef-a9a9-4028-9a41-adcdc17a105b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2Fd2Bsf6uRh6mMyiWp4ISt%2Fimage.png?alt=media&amp;token=f4606d60-624f-4473-b649-81c3ec1d97ef" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FvBIl13aJijgewzHiOtE6%2Fimage.png?alt=media&amp;token=3fa496c3-763f-4c5f-b3f6-ca464eff0715" alt=""><figcaption></figcaption></figure>

Here we have selected the SMB quick share option to share the disk volume for collaborated file share between our AD Authenticated clients&#x20;

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FDrMQYgFnCkIlVCkvcgMe%2Fimage.png?alt=media&amp;token=f1374531-c932-4f29-9149-fa7c42af8b18" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FW8ROYZ320OoYKEHFDHjz%2Fimage.png?alt=media&amp;token=5b725293-2602-42d3-afc4-079201fdefdf" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FEn9bXoxXLArjKuMK2uqp%2Fimage.png?alt=media&amp;token=957ea9bb-cb1e-48ac-9ff0-461851e58f88" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FLt4hu8YJYCUMI1e3DozZ%2Fimage.png?alt=media&amp;token=e4fa2649-6dae-4cf2-a2a9-9c3bbd1738bb" alt=""><figcaption></figcaption></figure>

Now we have created the AD file server and now we will try to access the server and create the Department wise folders and let the Department only view and access the server individually&#x20;

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FJGG4tAA7W97JvHokzrMC%2Fimage.png?alt=media&amp;token=f7c0c239-74c5-4167-afa4-62ede0ccb49c" alt=""><figcaption><p>The default file share path </p></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FYkB59IGpEyhzcX5HE9wy%2Fimage.png?alt=media&amp;token=f21a997d-7c92-461e-9d50-d44bc69c1f8f" alt=""><figcaption></figcaption></figure>

We have created all the folders based on the departments we have and now we will add the permissions to `READ, WRITE,EXECUTE` based on the groups so only the group user can access & view the respected departments (`EX: hruser will only be able to see HR group in here`)

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FGeL96O80EgCdk5fFxysT%2Fimage.png?alt=media&amp;token=4c1277b8-52aa-4b68-87b0-05edd3ae107d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2Fppn4YKTqifdiMOzk7g2s%2Fimage.png?alt=media&amp;token=f838996d-bd31-4c5b-aed3-208c323b3705" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FyH6NRycXc2w2U00afw7p%2Fimage.png?alt=media&amp;token=ababcca7-2c3e-400f-b3bc-ea7a9d28114d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FlxTqDBFT6opBims7CNNR%2Fimage.png?alt=media&amp;token=a6c1a9ae-b82a-45ca-9e59-3d67d7c8129f" alt=""><figcaption></figcaption></figure>

Here we can see the default folder access permissions given and now we will add the HR group to access the server and have full control over the HR folder&#x20;

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FNYmKmok2iV6I1oZ6TS5q%2Fimage.png?alt=media&amp;token=59d9246f-33bd-4aeb-96dc-5fa9a1523564" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FjNIvA95P4I39xIcZGyUU%2Fimage.png?alt=media&amp;token=7826c8d9-a1e9-4759-96b1-0dcdc00db08a" alt=""><figcaption></figcaption></figure>

***

#### Testing File server permissions :&#x20;

Now we have logged in with the hr user inside the HR group which means the HR folder will only visible inside th file share ..

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FruPhB3KRc6R7HmESnhPq%2Fimage.png?alt=media&amp;token=89498073-9016-4a94-bcc2-2d0976cc5cf3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FlUpXTewljbytrWZqa7Mg%2Fimage.png?alt=media&amp;token=2bfbd9a9-6d4c-4146-82ad-4679f5334b08" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FfndtqLSQeM9zr3fl1it1%2Fimage.png?alt=media&amp;token=4bd77c56-8bf4-415e-bc72-ad62f6b4b7b5" alt=""><figcaption></figcaption></figure>

We can only see the HR folder which means our AD file server is running as it should be and the File server permissions are also working as normal&#x20;

***

On Applying only the HR users can see the folder on the file server and will have the full access over it. Similiarly we will create permissions & Access control for all the folders respective to their groups and then we will test the same by adding the computer in the AD & accessing the file server in the next section.
