× NETGEAR will be terminating ReadyCLOUD service by July 1st, 2023. For more details click here.
Orbi WiFi 7 RBE973
Reply

Switching from Local to AD accounts

EKroboter
Apprentice

Switching from Local to AD accounts

Hi Everyone,

This might be a straightforward question, but I want ot make sure before I proceed.

We have a standard Windows Server 2008 R2 environment, a DC running AD, DNS and DHCP. The AD structure is already in place, OUs for computers, servers, users. User accounts, Groups, etc. Everything working perfectly fine.

 

Our RN516 is still using local account (this is becasue it was being used before the switch to AD) and I want to join it to the domain to be able to manage user account and permissions form a central location.

 

The NAS local accounts match the AD accounts names (name.lastname) and passwords. This allows authenticated users to browse the NAS and access files ans folders without having to enter credentials, since Windows will always try to use the domain account first, and since they match, it works.

 

However, the NAS local groups do not match the AD groups because it doesn't allow spaces in the name. A local group in the NAS would be named "Name-of-Department" and the same group in AD would be "Name of Department".

 

Several users also store personal files in their home folders (/data/home/name.lastname/)

 

Now, what would happen if I join the NAS to the domain in order to use the same user accounts and groups? I always set share permissions by group, so I keep everything as tidy as possible.  I already read through this article: http://kb.netgear.com/23152/How-do-I-configure-Active-Directory-mode-on-my-ReadyNAS-OS-6-storage-sys... and this other one http://kb.netgear.com/7066/ReadyNAS-OS-6-Setting-Active-Directory-folder-permissions?cid=wmt_netgear... but they don't cover what happens when switching from local to AD accounts.

 

My questions are:

1. Are individual share permissions reset when enabling AD accounts, in order to set permissions through Windows Explorer?

2. Do the local accounts dissapear? If they do, what happens to user's home folders?

3. Will I be able to set permissions through Frontview or only through Windows Explorer? Not really critical though.

4. Will the local default admin account work? Or will it be replaced by the AD's administrator account?

 

My goal is to have permissions set by group for each share, so that every user has access to the shares available to their group. There might be the odd ocassion that and individual user might need access to a share outside of its group, but I can either put the user int he group or add the permissions for that particualr share. 

 

I believe this is everything for now. Any help will be appreciated.

 

Thanks.

Model: RN51600|ReadyNAS 516 6-Bay
Message 1 of 4
EKroboter
Apprentice

Re: Switching from Local to AD accounts

So, after giving it much thought, I think the best course of action would be:

 

  1. Set the permissions for all the shares to Everyone read/write
  2. Reset File Access for every share
  3. Backup all user home folders with data on them
  4. Delete all users and groups. This will effectively leave just the admin account and every share with full access
  5. Reboot
  6. Join the NAS to AD and sync user accounts
  7. Check that everything works
  8. Restore the files to each home folder (I assume home folders will be re-created for every account on AD)
  9. Set Sharing permissions from within Windows Explorer
  10. Cross fingers

I can schedule some dowtime and do all of this during a weekend. If you have any other ideas please share.

Message 2 of 4
EKroboter
Apprentice

Re: Switching from Local to AD accounts

I´ll appreciate any contributions to this thread.

Model: RN51600|ReadyNAS 516 6-Bay
Message 3 of 4
mdgm-ntgr
NETGEAR Employee Retired

Re: Switching from Local to AD accounts

Yes that looks like a good plan. I would backup all data though, not just the home folders.

Message 4 of 4
Top Contributors
Discussion stats
  • 3 replies
  • 1993 views
  • 0 kudos
  • 2 in conversation
Announcements