> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning NTFS Security

> Capturing the shares and permissions of a file server through a reusable analysis package.

The *NTFS Security* scan module captures no systems, but the permission
structure of a file server: its shares and the rights granted on them. What
is captured is defined by an **analysis package** – a reusable compilation of
server, shares, domain and credentials.

<Note>
  This module captures the data. The permissions themselves are evaluated
  under [Analysis › File System](/docs/en/analysis/file-system).
</Note>

## The wizard

*NTFS Security* runs through five steps instead of four: *Basics* ›
*Authentication* › *NTFS Configuration* › *Schedule* › *Summary*.

Domain and credentials are mandatory in the *Authentication* step – unlike
with *Active Directory* and *Windows (AD)*, this scan may not run under the
gateway's service account.

## Choosing or building an analysis package

In the *NTFS Configuration* step you choose an existing analysis package under
*Analysis Package Selection* or put a new one together under *New Analysis
Package*: give it a name, add one server in the *File Servers* section – loaded
from Active Directory or entered as *Hostname or IP address* – and assign its
shares, individually or through *Select All Shares*. Administrative shares are
marked as *Admin*. To load the shares, the dialog needs a gateway and
credentials from the previous steps.

The analysis package is the fixed unit that every run scans again. Results of
later runs are only comparable as long as its scope stays the same.

<Note>
  An analysis package always carries exactly **one** server. A second file
  server means a second package.
</Note>

Missing credentials can be created directly from the dialog – the type is
restricted to *User Account* there.

<Tip>
  Limit the folder depth if you only want to evaluate the upper levels of a
  share at first. Leave the field empty and the job captures the full depth;
  the permitted values are in the
  [Scan Reference](/docs/en/scan/reference#bounds-of-the-number-fields).
</Tip>

The new package is created only after the wizard is completed, and then
stands under *Scan › Analysis Packages* ready for further jobs.

## Managing analysis packages

Under *Scan › Analysis Packages* you can also create a package independently
of a job. The dialog requires *Analysis Package Name*, *Domain*, *Server* and
at least one share; you choose *Gateway* and *Credentials* in addition. Choose
the gateway first: only then does the *Credentials* list also offer the
credentials stored on that gateway. If you change the gateway, the dialog clears
such a selection again.

Server selection has two modes, *From Active Directory* and *Enter Manually*.
*Load Servers from Active Directory* stays disabled until credentials, gateway
and domain are chosen. Through *Reload Shares* you fetch the current state. The
search for servers and shares can take a while; if you close the dialog during
the search, all input is lost after a confirmation.

Each entry in the list shows name and usage – the number of jobs or
*Not Used* – and, expanded, the *Shares* as well as, if present, the job
names under *Used in Jobs*.

<Warning>
  The confirmation when deleting names the consequence, but does not check
  whether the package is actually used in any job. Expand the entry beforehand
  to see that for yourself.
</Warning>

## Related

Which type this scan produces is under
[Storage, Backup, Permissions](/docs/en/assets/storage-backup) and
[Directory and Network Services](/docs/en/assets/directory-services).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.