Skip to main content
NetApp Knowledge Base

CIFS access denied when user domain group scope is domain local

Views:
1,023
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

Applies to

  • ONTAP 9
  • Active Directory Security Groups

Issue

  • Users are not able to access CIFS shares
  • Vserver is joined to Domain DOMB and the trusted domain is DOMA
  • Configure domain user group in share permission
  • User cannot be granted security group information when the user belongs to DOMA
  • The following is an example of configuring CIFS

#Trusted Domain A
Domain: DomainA.local
User: usera
Group: testgroupa(Group scope is domain local)

#Domain B
Domain: DomainB.local
User: userb
Group: testgroupb(Group scope is domain local)

#NetApp CIFS(Fail to login CIFS share due to permission deny)
CIFS Server: testcifs
Join Domain: DomainB.local
Share: cifsshare
Permission: DomainA\testgroupa

LAB_NA::*> secd authentication show-creds -node LAB_NA-01 -vserver testcifs -win-name domainA\usera

 UNIX UID: pcuser <> Windows User: domainA\usera (Windows Domain User)

 GID: pcuser
 Supplementary GIDs: 
  pcuser

 Primary Group SID: DomainA\Domain Users (Windows Domain group)

 Windows Membership:  >>> usera cannot be granted security group.
  LEOLAB\Domain Users (Windows Domain group)
   (Windows Well known group)
  NT AUTHORITY\ (Windows Well known group)
 User is also a member of Everyone, Authenticated Users, and Network Users

 Privileges (0x2000):
  SeChangeNotifyPrivilege

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.