ONTAP ABE does not hide SMB/CIFS share itself from users not in ACE
Applies to
- ONTAP 9
- SMB/CIFS shares
- Access-Based Enumeration (ABE)
- Access Control Entry (ACE)
Issue
- SMB/CIFS share configured with ABE enabled.
- Share-level ACE grants access only to a specific user or group (e.g.,
AD\Administrator). - Users not included in the ACE can still see the share (e.g.,
\\server\sharetest) in Windows Explorer. - Expected behavior: users not in ACE cannot see the share itself in the network browse list.
- Actual behavior: users not in ACE cannot access contents but can see the share name.
