Departments use file servers to more efficiently share files, as compared with emailing files.
Notes
- But as with any change in workflow, conventions may need to be discussed and agreed on, and new skills and habits developed.
- When and if it's a "go" per Physics's decision, PhysIT can make this server "drive" appear automatically so it becomes easily available on staff computers. This is almost immediate, once committed, via AD policy.
- Roger is working with Greg at A&S to set up the space (as of 11/15), in anticipation that this service will prove of value to Physics. This can easily be reversed if a "no go", of course.
November 2014
Phase one: Shared folders
Synonyms: Folders == directories.
Conventions used among staff will limit actions not necessarily enforced by the permissions.
Goal: Reduce complexity to reduce mistakes and facilitate debugging, balanced with ensuring security and adequate access.
Groups
Group name: PhysAdmin
Sub-group name | NetIDs | Members |
---|---|---|
Management
| jcm8 dah6 | John Miner Deb Hatfield |
Business | nbs4 | Nancy Searles |
Grad | klb79 | Kacey Acquilano |
Individual group members | klb79 rjf2 sfc1 ? | Kacey Acquilano Rosemary Barber Sue Sullivan Brad (temp) |
Folders and permissions
Top Level Directory | Folder name | Primary directory (folder) owner(s) (NetID) | Full folder access, by group or individual (NetID) | Notes |
---|---|---|---|---|
Instruction | Undergrad | Sue Sullivan (sfc1) | PhysAdmin | All staff |
Instruction | Duplicating | Brad (temp) | PhysAdmin | All staff |
Instruction | Course Mgmt | Rosemary Barber (rjf2) | PhysAdmin | All staff |
(none) | General and Central | Sue Sullivan (sfc1) | PhysAdmin | All staff |
(none) | Grad | Kacey Acquilano (klb79) | Grad, Management | |
(none) | Faculty | Deb Hatfield (dah6) | Grad, Management | Kacey needs access |
Business | HR and Staffing | Deb Hatfield (dah6), Nancy Searles (nbs4) | Business, Management | |
Business | Budget and Finance | Nancy Searles (nbs4), John Miner (jcm8) | Business, Management | |
(none) | Chair | Deb Hatfield (dah6) | Management |
SysAdmin Note:
- Permissions on shared dept folders will be applied only by groups, not ID's (Due in part to the complexity of tracking /adding / removing individual permissions applied to folders, as well as possible file inheritance & permissions settings.)
- Individual ID permissions should only be granted to folders in "Users" folder trees, if used. (Scripting / variables may be preferred)
- Groups should have a functional name (please) "Business office", "Instruction", etc.
- All Phy dept sub-groups will be put in a primary Physics Admin / dept group - which is used to apply policies, map drives, apply networked printer queues, allow access to the share, etc.
- A special
- All staff must be in at least one sub-group, and preferably only one - even if the group only contains one person. (To allow access to share, policy’s, etc.)
- Folders which everyone can access do not need finer grained permissions. (Use primary group @ root only)
- Groups may either be nested (HR in Business Office), or multiple groups may be given permission to a folder (Safety, Facilities), as appropriate.
- Where group nesting/ combining is not sufficient, a user may be placed in more than one group.
- Caution is advised with any nesting or combined group access, unintended future rights may result.
- It is desirable to use these same groups for all services, such as Group Policies, FileMaker, Printing, File Sharing, etc.
- Policies can only be applied to accounts which are in the AD Tree cornell.edu\CUinv\NetIDs\Staff\AS\, or are created by AS/ChemIT/Physit (Special admins, guestID's, etc.)
Phase two: Individual's folders
- TBD
Info from John Miner, to inform this:
Folder name | Primary directory (folder) owner (NetID) | Full folder access, by group or individual (NetID) | Notes |
---|---|---|---|
FACILITIES | JOHN | ||
MANAGER | JOHN | Q: Is this more a personal folder, not a "shared" folder? A: Sounds that way. "Users\jcm8" |