From soaring cloud costs to risk ownership, data sovereignty and legacy compatibility, there are many reasons why organizations continue to rely on file servers for inexpensive and abundant local storage. Yet no matter where your data lives, access governance is essential to keeping it in the right hands.
Even firmly into the cloud era, countless organizations continue to maintain on-premises file servers alongside their various SaaS subscriptions. These kinds of hybrid setups help businesses preserve large volumes of data while maintaining full control over cost, risk, retention, backups and access.
While the convenience of cloud services is still a big draw that drives many ongoing migration efforts, concerns like spiking subscription costs, data ownership and regulatory demands have caused others to pause or even rethink their cloud strategy.
So despite predictions of a gleaming, cloud-only future, it appears that the humble file server will stick around as an IT mainstay for years to come. No matter the reason your organization continues to rely on file servers, the important part is that you administer them securely and efficiently.
With the level of control and risk ownership that on-premises infrastructure affords you, effective access governance is essential to protecting your data.
Here are five best practices that every file server administrator needs to know.
#1: Never assign permissions directly to users
In order to grant a user access to a directory, you should always use a dedicated, single-purpose security group that follows a consistent naming scheme such as fs_finance_read.
Even though most admins are aware of this, sticking to the rule can be tricky in practice when some higher-up is shouting about how a team member needs access RIGHT NOW.
The problem with assigning access directly to users is that there is no way to track these one-off permissions. When you inspect a user object, you can see every group they are a member of. By naming groups after the permission they grant, this effectively doubles as a list of everything a user has access to.
However, when a user is privileged on a folder directly, the only place that permission shows up is in the properties of the folder itself. Even in a relatively small environment with only a few hundred directories, this makes one-off permissions effectively invisible.
A must-read for sysadmins: Our best practice guide lays out essential tips and tricks for governing access in Microsoft environments.
Clean up group structures, improve visibility and lower your workload – Dive in today!
Download Free White Paper
#2: Nest permission groups using the AGDLP model
As we’ve established, dedicated security groups are the best way to grant users access to file server directories. However, that does not mean you should add users directly to these security groups. File server administration becomes even more efficient when you add another layer of abstraction.
First, create global groups that map to the different roles in your organization: sales, customer support, human resources and so on. Next, make these global groups a member of the individual permission groups for each resource a user in that role needs access to.
By layering groups this way, you can now provide new users with all the access they need simply by adding them to the global role group that matches their job.
This approach is known as the AGDLP model, short for the nested structure of accounts, global groups, domain local groups and finally permissions. Following AGDLP or similar models allows you to implement a form of role-based access control for file server and Active Directory resources, streamlining access governance significantly.
#3: Set share permissions leniently, use NTFS to control access
Share permissions control access to network resources such as file shares. However, since NTFS permissions apply to both network and local access while also giving you more granular control over permission levels, most admins prefer to use NTFS permissions for governing access.
When NTFS and share permissions interact, the more restrictive permission level wins out. This makes it easiest to set share permissions to a high level – such as Change for users and Full Control for admins – while relying on NTFS permissions to restrict access from there.
#4: Avoid breaking inheritance
To streamline file server governance, focus on managing the top levels of your directory tree and let permissions propagate down from there. This works best with a clean folder structure that allows you to make full use of permission inheritance.
Ideally, you never want to set explicit permissions deeper than two or three levels down your directory tree.
Of course, admins rarely get to work under ideal conditions. Years of clutter plus leadership demands may force you to find workaround solutions in order to give users access to a specific project folder buried deep in a department share.
Even then, however, it can be easier to create new folders or move it up the directory tree rather than to overwrite inherited permission and deal with the knock-on effects on subfolders and files.

#5: Adhere to the Principle of Least Privilege
Users should only have access that is strictly necessary for their job and, even then, must hold the most restrictive permission level that still allows them to accomplish their task. The Principle of Least Privilege is a foundational concept of IT security that should inform all your decisions about access on file servers and beyond.
Importantly, the Principle of Least Privilege is more than just a one-time check the moment you grant a user access. Roles and responsibilities change over time, and so too can whether someone still needs access to a resource.
This permission may have fit their job duties when you assigned it, but is it still relevant after a month? A quarter? A year?
The only way to ensure that users privileges align with their day-to-day responsibilities is to review them periodically and revoke any that no longer serve a purpose. However, these kinds of privilege audits are challenging to implement without a centralized governance platform to track user permissions and manage access review policies.
Unfortunately, manual oversight simply is not up to the task when it comes to enforcing least privilege access.
Automated, best practice governance with tenfold
From nested permission groups to a clean folder structure, the right approach to file server administration will lower your workload while bringing order to the chaos.
Yet even if you follow every best practice in the book, managing file servers remains a very demanding and time-consuming task – especially as just one piece of your entire IT infrastructure.
There is only one way to deliver a truly seamless file server experience: A dedicated governance solution like tenfold. As a fully automated platform, tenfold can not only take over provisioning tasks, approval workflows and group management.
It also provides in-depth visibility into every level of your directory tree, showing you exactly who has access and why. Not just for your file server, but all local and cloud privileges.
With comprehensive Identity Governance from role-based access to lifecycle management, an in-depth Data Access Governance toolset and ever growing Event Auditing feature, tenfold combines three solutions in just one convenient platform. Track and manage access across on-prem file servers, cloud apps and beyond.
Book a personal demo to learn more about tenfold and discuss your use case with one of our specialists.
Sponsored and written by Tenfold Software.

