The NTFS Security scan module captures no systems, but the permission
structure of a file server: its shares and the rights granted on them. What
is captured is defined by an analysis package – a reusable compilation of
server, shares, domain and credentials.
The wizard
NTFS Security runs through five steps instead of four: Basics ›
Authentication › NTFS Configuration › Schedule › Summary.
Domain and credentials are mandatory in the Authentication step – unlike
with Active Directory and Windows (AD), this scan may not run under the
gateway’s service account.
Choosing or building an analysis package
In the NTFS Configuration step you choose an existing analysis package under
Analysis Package Selection or put a new one together under New Analysis
Package: give it a name, add one server in the File Servers section – loaded
from Active Directory or entered as Hostname or IP address – and assign its
shares, individually or through Select All Shares. Administrative shares are
marked as Admin. To load the shares, the dialog needs a gateway and
credentials from the previous steps.
The analysis package is the fixed unit that every run scans again. Results of
later runs are only comparable as long as its scope stays the same.
An analysis package always carries exactly one server. A second file
server means a second package.
Missing credentials can be created directly from the dialog – the type is
restricted to User Account there.
Limit the folder depth if you only want to evaluate the upper levels of a
share at first. Leave the field empty and the job captures the full depth;
the permitted values are in the
Scan Reference.
The new package is created only after the wizard is completed, and then
stands under Scan › Analysis Packages ready for further jobs.
Managing analysis packages
Under Scan › Analysis Packages you can also create a package independently
of a job. The dialog requires Analysis Package Name, Domain, Server and
at least one share; you choose Gateway and Credentials in addition. Choose
the gateway first: only then does the Credentials list also offer the
credentials stored on that gateway. If you change the gateway, the dialog clears
such a selection again.
Server selection has two modes, From Active Directory and Enter Manually.
Load Servers from Active Directory stays disabled until credentials, gateway
and domain are chosen. Through Reload Shares you fetch the current state. The
search for servers and shares can take a while; if you close the dialog during
the search, all input is lost after a confirmation.
Each entry in the list shows name and usage – the number of jobs or
Not Used – and, expanded, the Shares as well as, if present, the job
names under Used in Jobs.
The confirmation when deleting names the consequence, but does not check
whether the package is actually used in any job. Expand the entry beforehand
to see that for yourself.
Which type this scan produces is under
Storage, Backup, Permissions and
Directory and Network Services.