Jan
27

Access to files and folders based on location

An american partner of RES posted this question to Bob Janssen:

We have doctors that can have read/write access to information on a particular file share when they’re at the hospital, but when they go home they only need read access. Nurses are another example where they can have read/write access to the information required, but when they go home they should have no access to this data.
Bob emailed them this solution:
Step 1: Block access to the file share
Step 2: Allow read access to the file share for nurses in hospital
Step 3: Allow read/write access to the file share for doctors in hospital
Step 4: Allow read access to the file share for doctors NOT in hospital

\\fileserver\data” is the file share in question.
“Hospital” is a PowerZone describing when a Workspace Session runs in the hospital (based on client IP-address, client name or other rules).
“Doctors” is an Active Directory group containing all user accounts for doctors.
“Nurses” is an Active Directory group containing all user accounts for nurses.

Step 1: Block access to the file share
Create a rule under “Files and Folders” located under “Security Management”:


Step 2: Allow read access to the file share for nurses in hospital
Create a rule under “Global Authorized Files” located under “Security Management”:
Step 3: Allow read/write access to the file share for doctors in hospital
Create a rule under “Global Authorized Files” located under “Security Management”:

Step 4: Allow read access to the file share for doctors NOT in hospital
Create a rule under “Global Authorized Files” located under “Security Management”:

Endresult
Security Management\Files and Folders

Security Management\Global Authorized Files

COMMENTS: 0
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

 
CATEGORIES:
ARCHIVES: