The information in this article applies to:
SUMMARY
This article explains how to access network drives created in services.
Even though network drives are global system resources, they can only be
accessed by processes running under the security context which was used to
establish the network connection.
MORE INFORMATION
For the purpose of this article, assume the following configuration:
1.Network Connection made with Service1When a network connection is established under "Service1," the "User1" credentials are used (such as, domain "DOMAIN," user "User1" and their password):NET USE X: \\ASERVER\SHARE The drive X: is mapped to \\ASERVER\SHARE and can only be used by Processes which have validated this credentials of DOMAIN\User1. Therefore only the following processes can access the network drive X:
2.Network Connection made with the option NET USE /USERWhen a network connection is made with NET USE /USER:'Domain\Auser', the redirector sends an Server Message Block (SMB) frame "C Session setup" to the server in order to validate the credentials of "Domain\Auser." The server creates an access token for this user and replies to the redirector with an SMB frame "R Session setup" including a user ID that will be used in all consecutive SMB frames related to the connection.NET USE X: \\ASERVER\SHARE /USER:DOMAIN\Auser The drive X: is mapped to \\ASERVER\SHARE and can only be used by processes which have validated the credentials of DOMAIN\AUser. Therefore only the following processes can access the network drive X:
Q103390 Network Access Validation Algorithm and Example Additional query words: prodnt
Keywords : kbnetwork nthowto ntnetserv NTSrvWkst |
Last Reviewed: January 4, 2000 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |