Sharing a Folder Using RBAC
Learn the essential steps to install and configure Windows Server OS for your enterprise environment.

Sharing a Folder Using RBAC in Windows Server 2024

RBAC in Windows Server 2024

In Windows Server 2024, implementing folder sharing with RBAC (Role-Based Access Control) means using NTFS permissions and share permissions in combination with security groups in Active Directory to control access based on user roles.

βœ… Step-by-Step Guide: Sharing a Folder Using RBAC in Windows Server 2024

πŸ›  Prerequisites:

  • Windows Server 2024 with File Server role installed
  • Folder to share (e.g., D:\DepartmentDocs)
  • Active Directory roles/groups created (e.g., HR_Read, HR_Write, IT_Admin)

πŸ”Ή Step 1: Create Role-Based AD Security Groups

  1. Open Active Directory Users and Computers.
  2. Navigate to your desired OU.
  3. Create security groups for each role:
    1. HR_Read – read-only access to HR folder
    1. HR_Write – modify access
    1. IT_Admin – full control
  4. Add users to the appropriate group based on their job role.

πŸ”Ή Step 2: Create or Identify the Folder to Share

Let’s say the folder is D:\DepartmentDocs.

  • Right-click the folder β†’ Properties
  • Go to the Sharing tab β†’ Click Advanced Sharing
  • Check Share this folder
  • Set a Share name (e.g., DepartmentDocs)
  • Click Permissions:
    • Remove Everyone
    • Add your role-based groups:
      • HR_Read β†’ Read
      • HR_Write β†’ Change
      • IT_Admin β†’ Full Control
    • Click OK

πŸ”Ž Share permissions are broadβ€”NTFS permissions provide finer control.

πŸ”Ή Step 3: Set NTFS Permissions (File System Access)

  • Go to the Security tab β†’ Click Edit
  • Remove unwanted groups like Everyone or Users
  • Add the same AD groups:
    • HR_Read β†’ Allow: Read & execute, List folder contents, Read
    • HR_Write β†’ Allow: Modify
    • IT_Admin β†’ Allow: Full control
  • Click OK

βœ… NTFS permissions are what actually control what users can do inside the folder.

πŸ”Ή Step 4: Test Access

From a client machine or another domain-joined PC:

  • Open \\ServerName\DepartmentDocs
  • Log in as different users and confirm:
    • Read-only users can view files, not edit
    • Modify users can add/edit/delete
    • Admins can do everything

πŸ›‘ Optional: Enable Access-Based Enumeration (ABE)

To hide folders users don’t have access to:

  1. Open Server Manager β†’ File and Storage Services
  2. Click on Shares
  3. Right-click the share β†’ Properties
  4. Under Settings, enable Access-based Enumeration

🎯 Summary

Role/GroupShare PermissionNTFS Permission
HR_ReadReadRead & execute
HR_WriteChangeModify
IT_AdminFull ControlFull Control

🎯 RBAC works best when you manage access through AD groups, not individual user permissions.

Install and configure Windows Serverβ€―2025

2 Comments

Leave a Reply

Your email address will not be published. Required fields are marked *