{"id":553,"date":"2025-10-28T21:14:59","date_gmt":"2025-10-28T21:14:59","guid":{"rendered":"https:\/\/carlostech.com\/?p=553"},"modified":"2026-02-25T20:27:26","modified_gmt":"2026-02-25T20:27:26","slug":"active-directory-part-3","status":"publish","type":"post","link":"https:\/\/carlostech.com\/?p=553","title":{"rendered":"Active Directory Lab 3 &#8211; GPOs, Service Accounts, Permissions"},"content":{"rendered":"\n<p>In our final Active Directory lab, we&#8217;ll showcase the power of GPOs and enterprise file management. We&#8217;ll set up shared network drives deployed through Group Policy, use File Server Resource Manager to control storage, configure folder permissions, implement access-based enumeration so users only see what they can access, and create service accounts to run services with limited, specific permissions. <br><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>Shared Network Drive<\/strong><\/p>\n<\/blockquote>\n<\/blockquote>\n\n\n\n<p>Will be mapped to all domain users using a GPO.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-87-1024x575.png\" alt=\"\" class=\"wp-image-554\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-87-1024x575.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-87-300x168.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-87-768x431.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-87-1536x862.png 1536w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-87-1140x640.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-87.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>This GPO would be under User Preference -&gt; Windows Settings -&gt; Drive Maps. The first thing it asks for is the location (<strong>file path<\/strong>) of this network drive. But before we jump into the GPO configuration, let me show you why using GPOs for this is critical instead of manually mapping drives<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-88-1024x575.png\" alt=\"\" class=\"wp-image-555\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-88-1024x575.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-88-300x168.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-88-768x431.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-88-1536x862.png 1536w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-88-1140x640.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-88.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We need to know the actual hostname of the server to be able to correctly input the file path. So, in the command line we used the command \u201c<strong>hostname\u201d<\/strong> on the server.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-89-1024x575.png\" alt=\"\" class=\"wp-image-556\" style=\"aspect-ratio:1.7808990625103522;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-89-1024x575.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-89-300x168.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-89-768x431.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-89-1536x862.png 1536w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-89-1140x640.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-89.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Then, in the File Explorer, right click the empty space and created a new folder named SHARED.&nbsp;<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-90-1024x575.png\" alt=\"\" class=\"wp-image-557\" style=\"aspect-ratio:1.7808990625103522;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-90-1024x575.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-90-300x168.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-90-768x431.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-90-1536x862.png 1536w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-90-1140x640.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-90.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Share the folder with the network and look at the two different kinds of permissions available directly on the folder.&nbsp;<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-91-1024x575.png\" alt=\"\" class=\"wp-image-558\" style=\"aspect-ratio:1.7808990625103522;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-91-1024x575.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-91-300x168.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-91-768x431.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-91-1536x862.png 1536w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-91-1140x640.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-91.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Notice that you can add users and groups, and configure their permissions for this folder. However, these Share permissions are extremely basic as there are only three options:\n<ul class=\"wp-block-list\">\n<li>Read &#8211; view files only<\/li>\n\n\n\n<li>Change &#8211; read and modify files<\/li>\n\n\n\n<li>Full Control &#8211; complete control over the share<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>These Share permissions only apply when someone accesses the folder <strong>over the network<\/strong>. They don&#8217;t affect someone sitting at the server itself.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-92-1024x575.png\" alt=\"\" class=\"wp-image-559\" style=\"aspect-ratio:1.7808990625103522;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-92-1024x575.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-92-300x168.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-92-768x431.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-92-1536x862.png 1536w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-92-1140x640.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-92.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>To configure more granular permissions, you need to use <strong>NTFS permissions<\/strong> found in the Security tab. NTFS permissions:\n<ul class=\"wp-block-list\">\n<li>Apply <strong>both locally and over the network<\/strong> .<\/li>\n\n\n\n<li>Offer much more control. <\/li>\n\n\n\n<li>Can be set on individual files, not just folders.<\/li>\n\n\n\n<li>Are what you&#8217;ll use most of the time for real security.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>When accessing a shared folder over the network, <strong>both<\/strong> Share and NTFS permissions apply &#8211; and the <strong>most restrictive<\/strong> permission holds priority. <\/p>\n\n\n\n<p>We shared the folder over the network and established the permissions. Peter is under the group \u201cDomain Users\u201d so he should have read rights and have access to the folder over the network.&nbsp;<br><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-93-1024x575.png\" alt=\"\" class=\"wp-image-560\" style=\"aspect-ratio:1.7808990625103522;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-93-1024x575.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-93-300x168.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-93-768x431.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-93-1536x862.png 1536w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-93-1140x640.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-93.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>As you can see, the folder does <strong>not<\/strong> automatically appear in Peter&#8217;s File Explorer. That is because sharing the folder is only making it available over the network \u2013 it isn&#8217;t pushed to users automatically. This works exactly like a public library \u2013 the book (file) is there to access but you must know where to look for it.&nbsp;<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-94-1024x575.png\" alt=\"\" class=\"wp-image-561\" style=\"aspect-ratio:1.7808990625103522;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-94-1024x575.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-94-300x168.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-94-768x431.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-94-1536x862.png 1536w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-94-1140x640.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-94.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The first option you have is to manually map the drive to the user profile as shown.<\/li>\n<\/ul>\n\n\n\n<p>When mapping drives manually, you have to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Input the file path for <strong>every single user<\/strong>.<\/li>\n\n\n\n<li>Visit each user&#8217;s computer (or remote in).<\/li>\n\n\n\n<li>Make sure to check <strong>&#8220;Reconnect at sign-in&#8221;<\/strong> so the drive persists after reboot.<\/li>\n<\/ul>\n\n\n\n<p>You can clearly see how tedious and time consuming this would be to configure at mass scale \u2013 which is why utilizing Active Directory and GPOs is crucial. I disconnected the shared drive from Peter\u2019s profile to see if the GPO we&#8217;ll create now works.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-95-1024x575.png\" alt=\"\" class=\"wp-image-562\" style=\"aspect-ratio:1.7808990625103522;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-95-1024x575.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-95-300x168.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-95-768x431.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-95-1536x862.png 1536w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-95-1140x640.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-95.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-96-1024x575.png\" alt=\"\" class=\"wp-image-563\" style=\"aspect-ratio:1.7808990625103522;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-96-1024x575.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-96-300x168.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-96-768x431.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-96-1536x862.png 1536w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-96-1140x640.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-96.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We created the GPO as explained before and linked it to the New York Users OU.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"832\" height=\"446\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-97.png\" alt=\"\" class=\"wp-image-565\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-97.png 832w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-97-300x161.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-97-768x412.png 768w\" sizes=\"auto, (max-width: 832px) 100vw, 832px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Let\u2019s sign into Peter\u2019s user profile and force update the GPO using the command line. I also checked all of the GPOs applied to Peter\u2019s user account using the \u201c<strong>gpresult \/r\u201d <\/strong>command.&nbsp;\n<ul class=\"wp-block-list\">\n<li>You can see that the &#8216;<strong>Mapping Drive<\/strong>&#8216; GPO we just created was applied to his user profile. You can also see how the &#8216;<strong>Restrict Control Panel&#8217;<\/strong> GPO was not applied to him from our previous AD project due to security filtering.&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"686\" height=\"403\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-98.png\" alt=\"\" class=\"wp-image-566\" style=\"aspect-ratio:1.7022615535889871;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-98.png 686w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-98-300x176.png 300w\" sizes=\"auto, (max-width: 686px) 100vw, 686px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The shared drive is now mapped to Peter\u2019s File Explorer again.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p><strong>File Server Resource Manager<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Now that we have our shared folder working, we need to <strong>manage<\/strong> it properly. What if users start storing massive video files? What if someone uploads executable files that could be malicious? How do we control storage usage? The solution to all of these questions is utilizing File Server Resource Manager, which has these capabilities and more:\n<ul class=\"wp-block-list\">\n<li>Set storage quotas (limit how much space users can use).<\/li>\n\n\n\n<li>Block certain file types (like .exe or .mp3 files).<\/li>\n\n\n\n<li>Generate reports on storage usage.<\/li>\n\n\n\n<li>Send email alerts when quotas are exceeded.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"966\" height=\"679\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-99.png\" alt=\"\" class=\"wp-image-567\" style=\"aspect-ratio:1.4227115145420384;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-99.png 966w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-99-300x211.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-99-768x540.png 768w\" sizes=\"auto, (max-width: 966px) 100vw, 966px\" \/><\/figure>\n\n\n\n<p>Our AD server doesn&#8217;t have FSRM installed by default, so let&#8217;s add it now.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You should configure your server remotely as much as possible using RSAT &#8211; which is a standard security posture. However, the File Server Resource Manager Tools were not working on my remote admin computer. After some troubleshooting, I discovered that the Filer Server Resource Manager was pointing to the local machine instead of the server, and when I tried to point it to the server, the firewall on the server itself was blocking the connection.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"802\" height=\"245\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-100.png\" alt=\"\" class=\"wp-image-568\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-100.png 802w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-100-300x92.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-100-768x235.png 768w\" sizes=\"auto, (max-width: 802px) 100vw, 802px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Here you can see me enabling the firewall rules to allow me to remotely manage the files.&nbsp;<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"762\" height=\"197\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-101.png\" alt=\"\" class=\"wp-image-569\" style=\"aspect-ratio:3.868131868131868;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-101.png 762w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-101-300x78.png 300w\" sizes=\"auto, (max-width: 762px) 100vw, 762px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>And now the service on my remote admin computer points to the actual server, so the RSAT works now.&nbsp;<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"877\" height=\"610\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-102.png\" alt=\"\" class=\"wp-image-570\" style=\"aspect-ratio:1.4377406931964056;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-102.png 877w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-102-300x209.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-102-768x534.png 768w\" sizes=\"auto, (max-width: 877px) 100vw, 877px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Using FSRM&#8217;s <strong>file screening<\/strong> feature to prevent users from uploading audio and video files to this shared folder as these media files can consume massive amounts of storage space.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1020\" height=\"667\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-103.png\" alt=\"\" class=\"wp-image-571\" style=\"aspect-ratio:1.5292712066905616;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-103.png 1020w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-103-300x196.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-103-768x502.png 768w\" sizes=\"auto, (max-width: 1020px) 100vw, 1020px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>To prevent this shared folder from consuming all of our server storage, we&#8217;re going to implement a <strong>10 GB hard quota<\/strong>. As it is a hard quota, users cannot exceed this limit. Once they reach 10GB, any additional uploads will fail. <\/li>\n\n\n\n<li>Once a user reaches 85% of their threshold, I will receive an email notifying me of this and I can relay this information to the user(s) for proactive management. <\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"710\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-106-1024x710.png\" alt=\"\" class=\"wp-image-574\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-106-1024x710.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-106-300x208.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-106-768x533.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-106.png 1120w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Now let&#8217;s explicitly explain the difference between Share permissions and NTFS permissions using a real example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>As you can see in the image above, there&#8217;s a folder named &#8220;MARKETING.&#8221; In the <strong>Share permissions<\/strong>, only the Marketing Staff and Marketing Interns groups are listed &#8211; no other departments have access. <\/li>\n\n\n\n<li>The Marketing Interns group also have <strong>Full Control<\/strong> at the Share permissions level.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"696\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-105-1024x696.png\" alt=\"\" class=\"wp-image-573\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-105-1024x696.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-105-300x204.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-105-768x522.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-105-1140x775.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-105.png 1159w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>However, in the NTFS permissions, the Marketing Interns <strong>only<\/strong> have <strong>&#8220;Read&#8221;<\/strong> rights. So which permission actually applies?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The <strong>more restrictive policy always<\/strong> applies! It does not matter whether the restriction comes from Share permissions or NTFS permissions &#8211; when a user accesses a folder over the network, <strong>both<\/strong> sets of permissions are evaluated, and the most restrictive one is enforced.\n<ul class=\"wp-block-list\">\n<li>If the folder is accessed locally, only the NTFS permissions are evaluated.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>NTFS provides much more granular control versus Share permissions and because of this, IT admins may give users full &#8220;share&#8221; permissions but actually configure the specific permissions within NTFS so the users&#8217; permissions are not controlled by a broad scope share permission.\n<ul class=\"wp-block-list\">\n<li>You do not want to give read and execute rights in NTFS and only read rights in share permissions, as then that &#8220;user\/group&#8221; will only have read rights.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>Summary of Cross-Domain Permissions:<\/strong><\/p>\n\n\n\n<p><strong>\u2705<\/strong><strong> Global Groups:<\/strong> Can be used for permissions in other domains<br><strong>\u274c<\/strong><strong> Domain Local Groups:<\/strong> Cannot be used for permissions in other domains<br><strong>\u2705<\/strong><strong> Universal Groups:<\/strong> Can be used for permissions in any domain (easiest for multi-domain)<\/p>\n\n\n\n<p><strong><em>Inheritance<\/em><\/strong><\/p>\n\n\n\n<p>We have a folder named &#8220;<strong>Software&#8221;<\/strong> for our IT Department on our server. The <strong>entire<\/strong> IT Department should have access and read\/write permissions on this folder. However, there is a subfolder named <strong>&#8220;Licenses&#8221;<\/strong> that <strong>only<\/strong> the IT Managers should have access to.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"547\" height=\"611\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-114.png\" alt=\"\" class=\"wp-image-597\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-114.png 547w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-114-269x300.png 269w\" sizes=\"auto, (max-width: 547px) 100vw, 547px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The dilemma: Every subfolder within a parent folder has inheritance enabled. This means that whatever permissions a user or group has on the parent folder will automatically apply to all subfolders and files within it.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"637\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-109-1024x637.png\" alt=\"\" class=\"wp-image-577\" style=\"aspect-ratio:1.6075593564978172;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-109-1024x637.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-109-300x187.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-109-768x478.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-109.png 1135w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Look at the subfolder <strong>&#8220;Licenses<\/strong>&#8221; in the image above. Every group has at least read &amp; execute privileges. We need to click on the disable inheritance button &#8211; and it will give you two options.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"742\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-108-1024x742.png\" alt=\"\" class=\"wp-image-576\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-108-1024x742.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-108-300x217.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-108-768x557.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-108.png 1116w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We chose the &#8220;<strong>Remove all inherited permissions<\/strong>&#8221; option to have a clean slate for this subfolder as evident in the image above.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"687\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-107-1024x687.png\" alt=\"\" class=\"wp-image-575\" style=\"aspect-ratio:1.4905592369756286;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-107-1024x687.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-107-300x201.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-107-768x515.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-107-404x270.png 404w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-107-1140x765.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-107.png 1160w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We added the IT-Management group for the Licenses subfolder with full permissions for them. Now they&#8217;re the only group or users who have access to this subfolder.\n<ul class=\"wp-block-list\">\n<li>It is best practice to include &#8220;SYSTEM&#8221; and at least &#8220;ADMINISTRATORS&#8221; to the allowed groups to reduce the possibility of system malfunctions and to have a back up group for access.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"788\" height=\"466\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-117.png\" alt=\"\" class=\"wp-image-602\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-117.png 788w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-117-300x177.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-117-768x454.png 768w\" sizes=\"auto, (max-width: 788px) 100vw, 788px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Remember our Marketing folder that only the marketing department and its interns were able to access? Well, I tried to access it with Peter, a user in the IT group, to demonstrate this:\n<ul class=\"wp-block-list\">\n<li>Peter is completely unable to access the Marketing folder.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>One last scenario to showcase how &#8220;<strong>deny&#8221;<\/strong> permissions always trump &#8220;<strong>allow&#8221;<\/strong>:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"709\" height=\"717\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-116.png\" alt=\"\" class=\"wp-image-601\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-116.png 709w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-116-297x300.png 297w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-116-75x75.png 75w\" sizes=\"auto, (max-width: 709px) 100vw, 709px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We have a folder named &#8220;<strong>Project<\/strong>&#8221; that the IT department will use. The folder is shared to everyone in the IT department and I included Peter separately to demonstrate the &#8220;<strong>deny&#8221;<\/strong> permission. Peter is <strong>also <\/strong>part of the IT department (from our previous AD project).<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"603\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-118.png\" alt=\"\" class=\"wp-image-604\" style=\"aspect-ratio:1.4063358359274858;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-118.png 848w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-118-300x213.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-118-768x546.png 768w\" sizes=\"auto, (max-width: 848px) 100vw, 848px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Peter has access to the Project folder, as evident in the image above. However, Peter is new to the company and currently should <strong>not<\/strong> have access to the &#8220;Confidential&#8221; folder.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"698\" height=\"645\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-122.png\" alt=\"\" class=\"wp-image-609\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-122.png 698w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-122-300x277.png 300w\" sizes=\"auto, (max-width: 698px) 100vw, 698px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>I tried to delete Peter himself from the folder&#8217;s NTFS permissions but was denied as a result of inheritance.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"548\" height=\"587\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-119.png\" alt=\"\" class=\"wp-image-605\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-119.png 548w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-119-280x300.png 280w\" sizes=\"auto, (max-width: 548px) 100vw, 548px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>As you can see, the <strong>&#8220;allow&#8221; <\/strong>permissions are grayed out and are not available to edit due to the inheritance we discussed earlier. Peter <strong>can <\/strong>open this folder as of right now.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"652\" height=\"496\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-120.png\" alt=\"\" class=\"wp-image-606\" style=\"width:122px\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-120.png 652w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-120-300x228.png 300w\" sizes=\"auto, (max-width: 652px) 100vw, 652px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We&#8217;re applying a <strong>deny<\/strong> permission to prevent Peter from reading the contents of this folder. Since a deny permission always overrides an allow permission, Peter will not be able to read the folder&#8217;s contents and as such, Peter automatically cannot perform any higher-level actions either (such as modify and execute). \n<ul class=\"wp-block-list\">\n<li>Denying at the Read level blocks everything above it as well. <\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"750\" height=\"483\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-121.png\" alt=\"\" class=\"wp-image-607\" style=\"width:545px;height:auto\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-121.png 750w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-121-300x193.png 300w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>And now Peter has no access to the Confidential folder even though he has &#8220;allow&#8221; permissions that were enabled through inheritance from the parent folder. <\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong><em>Access-Based Enumeration <\/em><\/strong><\/p>\n<\/blockquote>\n\n\n\n<p>Remember earlier how the Marketing folder&#8217;s shared permissions only had the Marketing department and its interns, yet Peter, in the IT group, was able to find it?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Well, we can configure folder permissions so that if a user or group doesn&#8217;t have access to a folder, <strong>that folder won&#8217;t even appear<\/strong> when they browse the share. It&#8217;s completely invisible to them.<\/li>\n<\/ul>\n\n\n\n<p><strong>Why this is valuable:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Reduces helpdesk tickets<\/strong> &#8211; Users don&#8217;t see folders they can&#8217;t access, so they don&#8217;t ask &#8220;why can&#8217;t I open this?&#8221;<\/li>\n\n\n\n<li><strong>Improves security<\/strong> &#8211; Users can&#8217;t even attempt to access folders they shouldn&#8217;t know about.<\/li>\n\n\n\n<li><strong>Cleaner experience<\/strong> &#8211; Users only see what&#8217;s relevant to them, making shared drives less cluttered and confusing.<\/li>\n<\/ul>\n\n\n\n<p><strong>Our scenario:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We have a shared folder called <strong>&#8220;Shared&#8221;<\/strong> with two subfolders inside:\n<ul class=\"wp-block-list\">\n<li><strong>HR<\/strong> subfolder &#8211; for Human Resources documents.<\/li>\n\n\n\n<li><strong>IT<\/strong> subfolder &#8211; for IT department files.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>We want users from the IT security group to only be able to see the IT folder and users from the HR group to only be able to see the HR folder. Each department should not even know the other folder exists. <\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"744\" height=\"690\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-138.png\" alt=\"\" class=\"wp-image-674\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-138.png 744w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-138-300x278.png 300w\" sizes=\"auto, (max-width: 744px) 100vw, 744px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Only sharing the HR-subfolder to the HR group with read rights.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"979\" height=\"642\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-139.png\" alt=\"\" class=\"wp-image-675\" style=\"aspect-ratio:1.5249333408974868;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-139.png 979w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-139-300x197.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-139-768x504.png 768w\" sizes=\"auto, (max-width: 979px) 100vw, 979px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Not letting me remove regular Users from this HR subfolder in NTFS due to inheritance. We are going to disable inheritance but this time &#8211; we are going to convert inherited permissions into explicit permissions as we do not want to have a clean slate.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"715\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-140-1024x715.png\" alt=\"\" class=\"wp-image-676\" style=\"aspect-ratio:1.4321869089165358;object-fit:cover;width:64px\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-140-1024x715.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-140-300x210.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-140-768x536.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-140.png 1038w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Now IT should not have access to this folder whatsoever.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"756\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-141-1024x756.png\" alt=\"\" class=\"wp-image-677\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-141-1024x756.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-141-300x221.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-141-768x567.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-141.png 1038w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Configured the share permissions on the parent folder<strong>, &#8216;DeptShares<\/strong>&#8216; so it is only shared to the HR and IT departments with read rights only.<\/li>\n<\/ul>\n\n\n\n<p>Correct permissions are applied so now we activate <strong>Access-Based Enumeration,<\/strong> which completely hides folders from users who shouldn&#8217;t be seeing it in the first place.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-143-1024x683.png\" alt=\"\" class=\"wp-image-679\" style=\"aspect-ratio:1.4992888417882142;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-143-1024x683.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-143-300x200.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-143-768x512.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-143-404x270.png 404w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-143-1140x761.png 1140w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-143.png 1241w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Within Server Manager, go to File and Storage Services -&gt; Shares, right click -&gt; Properties and finally Settings on the folder you want to activate ABE on.\n<ul class=\"wp-block-list\">\n<li>Ensure that this is the parent folder that contains the subfolders you want to hide.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"998\" height=\"740\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-144.png\" alt=\"\" class=\"wp-image-681\" style=\"aspect-ratio:1.348652852340575;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-144.png 998w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-144-300x222.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-144-768x569.png 768w\" sizes=\"auto, (max-width: 998px) 100vw, 998px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Now ABE is activated for this share. When Peter (who is in the IT group) opens the <strong>&#8220;DeptShares<\/strong>&#8221; folder, he will not even know the existence of the HR folder.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"253\" height=\"98\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-145.png\" alt=\"\" class=\"wp-image-685\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The folder is properly shared with Peter.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"361\" height=\"166\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-146.png\" alt=\"\" class=\"wp-image-686\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-146.png 361w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-146-300x138.png 300w\" sizes=\"auto, (max-width: 361px) 100vw, 361px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Peter is unable to see the HR folder &#8211; he doesn&#8217;t even know it exists.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"452\" height=\"231\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-147.png\" alt=\"\" class=\"wp-image-687\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-147.png 452w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-147-300x153.png 300w\" sizes=\"auto, (max-width: 452px) 100vw, 452px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Yet, it&#8217;s clearly here locally on the server.<\/li>\n<\/ul>\n\n\n\n<p>Access-Based Enumeration successfully accomplished!<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Now we are going back to a GPO we previously configured on a prior project to see if they apply to Peter.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"465\" height=\"328\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-148.png\" alt=\"\" class=\"wp-image-689\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-148.png 465w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-148-300x212.png 300w\" sizes=\"auto, (max-width: 465px) 100vw, 465px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We are going to reset Peter&#8217;s password and force him to change it when he logs on again through Active Directory&#8217;s Users and Accounts. <\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"626\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-149-1024x626.png\" alt=\"\" class=\"wp-image-690\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-149-1024x626.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-149-300x183.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-149-768x470.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-149.png 1086w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Recall our password policy GPO we applied to all computers.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-150.png\" alt=\"\" class=\"wp-image-692\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-150.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-150-300x225.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-150-768x576.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Forcing us to change the password.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-151.png\" alt=\"\" class=\"wp-image-693\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-151.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-151-300x225.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-151-768x576.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>And it works!<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong><em>Implementing Service Accounts<\/em><\/strong><\/p>\n<\/blockquote>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1019\" height=\"601\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-152.png\" alt=\"\" class=\"wp-image-696\" style=\"aspect-ratio:1.6955246475541679;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-152.png 1019w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-152-300x177.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-152-768x453.png 768w\" sizes=\"auto, (max-width: 1019px) 100vw, 1019px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>First step is creating a &#8216;user&#8217; account in the &#8216;Servers&#8217; OU.\n<ul class=\"wp-block-list\">\n<li>Used the &#8216;$&#8217; symbol as the prefix to the username to indicate it is a service account and not a real user. <\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"667\" height=\"665\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-154.png\" alt=\"\" class=\"wp-image-700\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-154.png 667w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-154-300x300.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-154-150x150.png 150w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-154-75x75.png 75w\" sizes=\"auto, (max-width: 667px) 100vw, 667px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Fill in whatever details you may need to.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"774\" height=\"446\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-155.png\" alt=\"\" class=\"wp-image-702\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-155.png 774w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-155-300x173.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-155-768x443.png 768w\" sizes=\"auto, (max-width: 774px) 100vw, 774px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>On the target machine, we&#8217;re going to download the &#8220;<strong>Sysinternals Suite&#8221;<\/strong> &#8211; this provides a large array of different tools that we can implement.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"716\" height=\"513\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-156.png\" alt=\"\" class=\"wp-image-704\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-156.png 716w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-156-300x215.png 300w\" sizes=\"auto, (max-width: 716px) 100vw, 716px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Some of the many different kinds of services present in this suite.<\/li>\n\n\n\n<li>We&#8217;re going to use Autologon64 as we want this machine to <strong>always<\/strong> automatically log on to the same account.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"516\" height=\"305\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-157.png\" alt=\"\" class=\"wp-image-705\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-157.png 516w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-157-300x177.png 300w\" sizes=\"auto, (max-width: 516px) 100vw, 516px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Put the corresponding information in these fields.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"403\" height=\"260\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-158.png\" alt=\"\" class=\"wp-image-706\" style=\"aspect-ratio:1.5500624219725343;object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-158.png 403w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-158-300x194.png 300w\" sizes=\"auto, (max-width: 403px) 100vw, 403px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"535\" height=\"381\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-159.png\" alt=\"\" class=\"wp-image-708\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-159.png 535w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-159-300x214.png 300w\" sizes=\"auto, (max-width: 535px) 100vw, 535px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Restarting the machine to see if it applied.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"821\" height=\"534\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-160.png\" alt=\"\" class=\"wp-image-709\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-160.png 821w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-160-300x195.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-160-768x500.png 768w\" sizes=\"auto, (max-width: 821px) 100vw, 821px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>And it did! Without me having to type in anything, it automatically logged into our new service account.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-181.png\" alt=\"\" class=\"wp-image-923\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-181.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-181-300x225.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-181-768x576.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Now we want this machine to always automatically go to my website on start up. \n<ul class=\"wp-block-list\">\n<li>The first step in accomplishing this is to configure your default browser to automatically direct you to whatever website you want on browser startup. <\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-191-1024x768.png\" alt=\"\" class=\"wp-image-1270\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-191-1024x768.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-191-300x225.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-191-768x576.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-191.png 1080w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Pressing &#8216;<strong>windows + R&#8217;<\/strong> and going to <strong>shell:startup <\/strong>to ensure Chrome is a startup program.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-192-1024x768.png\" alt=\"\" class=\"wp-image-1272\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-192-1024x768.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-192-300x225.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-192-768x576.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-192.png 1080w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Dragged Chrome into this folder.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-194-1024x768.png\" alt=\"\" class=\"wp-image-1393\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-194-1024x768.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-194-300x225.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-194-768x576.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-194.png 1157w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We want this device to also never sleep. <\/li>\n<\/ul>\n\n\n\n<p>Finally, we&#8217;re going to restrict all other users from being able to login into this machine through a GPO. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-195-1024x768.png\" alt=\"\" class=\"wp-image-1395\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-195-1024x768.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-195-300x225.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-195-768x576.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-195.png 1157w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create a &#8220;allow log on locally&#8221; GPO under Computer Configuration -&gt; Windows Settings -&gt; User Rights.\n<ul class=\"wp-block-list\">\n<li>Using &#8220;allow&#8221; instead of &#8220;deny&#8221; so there are no issues.  <\/li>\n\n\n\n<li>Only allow the specific types of accounts able to log into this machine.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-196-1024x768.png\" alt=\"\" class=\"wp-image-1396\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-196-1024x768.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-196-300x225.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-196-768x576.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-196.png 1157w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Link the GPO to the actual machine.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-197-1024x768.png\" alt=\"\" class=\"wp-image-1398\" style=\"object-fit:cover\" srcset=\"https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-197-1024x768.png 1024w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-197-300x225.png 300w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-197-768x576.png 768w, https:\/\/carlostech.com\/wp-content\/uploads\/2025\/10\/image-197.png 1157w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>I tried to sign in with Peter&#8217;s user account and was denied!<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-16018d1d wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/carlostech.com\/?page_id=1276\">Back to Projects<\/a><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Showcasing the power of GPOs and enterprise file management. Setting up shared network drives deployed through Group Policy, using File Server Resource Manager to control storage, configure folder permissions, implement access-based enumeration. Create service accounts. &hellip; <\/p>\n<p><a href=\"https:\/\/carlostech.com\/?p=553\" class=\"awp-btn awp-btn-secondary awp-btn-bubble\"><span class=\"screen-reader-text\">Active Directory Lab 3 &#8211; GPOs, Service Accounts, Permissions<\/span><i class=\"fa fa-arrow-right\"><\/i><span class=\"bubble_effect\"><span class=\"circle top-left\"><\/span><span class=\"circle top-left\"><\/span><span class=\"circle top-left\"><\/span><span class=\"button effect-button\"><\/span><span class=\"circle bottom-right\"><\/span><span class=\"circle bottom-right\"><\/span><span class=\"circle bottom-right\"><\/span><\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1301,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12,15],"tags":[2],"class_list":["post-553","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-active-directory","category-home","tag-active-directory"],"_links":{"self":[{"href":"https:\/\/carlostech.com\/index.php?rest_route=\/wp\/v2\/posts\/553","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/carlostech.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/carlostech.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/carlostech.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/carlostech.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=553"}],"version-history":[{"count":124,"href":"https:\/\/carlostech.com\/index.php?rest_route=\/wp\/v2\/posts\/553\/revisions"}],"predecessor-version":[{"id":2070,"href":"https:\/\/carlostech.com\/index.php?rest_route=\/wp\/v2\/posts\/553\/revisions\/2070"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/carlostech.com\/index.php?rest_route=\/wp\/v2\/media\/1301"}],"wp:attachment":[{"href":"https:\/\/carlostech.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=553"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/carlostech.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=553"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/carlostech.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=553"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}