{"id":3071,"date":"2019-11-12T09:35:02","date_gmt":"2019-11-12T16:35:02","guid":{"rendered":"http:\/\/wp.natsci.colostate.edu\/cnsit\/?p=3071"},"modified":"2022-04-25T14:37:31","modified_gmt":"2022-04-25T20:37:31","slug":"manage-rstor-group-access-with-grouper","status":"publish","type":"post","link":"https:\/\/cnsit.colostate.edu\/kb\/manage-rstor-group-access-with-grouper\/","title":{"rendered":"Manage RStor Group Access with Grouper"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">Below are instructions for configuring RStor to provide access to others within CNS or at CSU.<\/h4>\n\n\n\n<p>Please substitute your RStor&nbsp;folder\/Group name everywhere you see \u201cRStorGroup.\u201d\u202f&nbsp;\u202f&nbsp;<\/p>\n\n\n\n<p>At first, only the original owners and members you have access to this folder.  These were set in place when your RStor account and Group Share was created.\u202f Should you want to share this folder with others, group permissions management can be  accomplished\u00a0using a combination of RStor\u00a0folder permissions (security tab), and  groups defined using a university tool called Grouper.  Grouper is available by logging into\u00a0<a href=\"https:\/\/grouper.colostate.edu\/\">https:\/\/grouper.colostate.edu<\/a>\u00a0using your CSU NetID and CSU NetID password.\u00a0<\/p>\n\n\n\n<p>Groups created in Grouper are automatically provisioned in Active  Directory (the authority that RStor uses for file and folders security  permissions) using the following naming convention:\u202f&nbsp;<\/p>\n\n\n\n<p>gpr_csurs_natsci_<em>[grouper folder name]<\/em>_<em>[grouper group name]<\/em>\u202f&nbsp;<\/p>\n\n\n\n<p>For your RStor Group Share, CNSIT has created two Grouper groups on default.  One is an admins group and the other is a members group. <\/p>\n\n\n\n<p>Members of the admins group  (named&nbsp;<strong>gpr_csurs_natsci_RStorGroup_admins<\/strong>&nbsp;in  Active Directory)  have full control of  your RStor&nbsp;folder and can manage Grouper groups as well as set permissions in your RStor Group folders through the Windows security tab.\u202f You may add members to this initial admins group and\/or create additional groups within Grouper to help manage Grouper permissions and\/or define RStor&nbsp;folder security.\u202f\u202f<\/p>\n\n\n\n<p>Members of the initial members group will have access (edit) to the RStor Group folders, but cannot alter permissions through the security tab nor manage Grouper groups for this RStor folder.<\/p>\n\n\n\n<p><strong>ADVANCED:<\/strong> <strong>Managing permissions for your RStor&nbsp;folder using Grouper<\/strong> &#8211; with theoretical examples that stray from the default setup.\u202f&nbsp;<\/p>\n\n\n\n<p>The following steps detail how to create an additional group and assign\/restrict permissions to your RStor&nbsp;folders.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>Let\u2019s say you have created two folders in your RStorGroup folder as follows:\u202f\u202f<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"201\" src=\"https:\/\/cnsit.colostate.edu\/kb\/wp-content\/uploads\/2019\/11\/M8hDQ7Q-300x201-1.png\" alt=\"\" class=\"wp-image-3702\"\/><\/figure><\/div>\n\n\n\n<p>Initially, all members of your your admins and members groups have access to these folders. You would like to limit access to allow only a certain group of members to access the &#8220;Staff&#8221; folder.\u202f Additionally, you only want admins to access the &#8220;Private&#8221; folder.\u202f&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Logon to Grouper\u202fat  <a href=\"https:\/\/grouper.colostate.edu\/\">https:\/\/grouper.colostate.edu<\/a> <\/li><li>In the\u00a0<strong>Browse folders<\/strong>\u00a0section (lower left), expand\u00a0<strong>Root\/app\/CSU R-STOR\/NATSCI\/RStorGroup<\/strong><\/li><li>Verify that the <strong>RStorGroup<\/strong> folder is selected. The breadcrumbs at the top (middle) should show: <strong>Home > Root > app > CSU R-STOR > NATSCI > RStorGroup<\/strong><\/li><li>Click the green<strong>\u00a0+ Create new group button<\/strong>\u00a0(upper left).<\/li><li>The New group screen should appear.\u202f\u00a0\u202f\u00a0 <ul><li>Leave the \u201cCreate in this folder\u201d path as it is\u2026 it should say\u00a0<strong>app:CSUR-STOR:NATSCI:<\/strong> <strong>RStorGroup<\/strong><\/li><li>In the<strong>\u00a0Group name\u00a0<\/strong>field, type the name of the group you want to create. In this example:<strong> staff<\/strong>\u202f\u00a0<\/li><li>Leave the Group ID field as it is, do NOT edit.\u202f<\/li><li>Give a description about this group, like: \u201c<strong>This staff group will contain users that will have access to the &#8220;Staff&#8221; folder<\/strong>.\u201d\u202f\u00a0<\/li><li>Click the\u00a0<strong>Save<\/strong>\u00a0button.\u202f<\/li><\/ul><\/li><li>Click on the new <strong>staff<\/strong>\u00a0group listed in the table.\u202f\u00a0 <ul><li>Verify you\u2019re viewing the staff group. The breadcrumbs at the top should show:\u00a0<strong>Home > Root > app > CSU R-STOR > NATSCI><\/strong> <strong>RStorGroup<\/strong> <strong>\u00a0> staff<\/strong>\u202f\u00a0<\/li><li>Click the orange<strong>\u00a0+ Add members<\/strong>\u00a0button (upper right)\u202f\u00a0<\/li><li>In the\u00a0<strong>Member name or ID<\/strong>\u00a0field, type the\u00a0NetID of the user (e.g.,\u00a0hsimpson)\u202f<\/li><li>Pick the correct user account from the suggestions shown.\u202f\u202f\u00a0<\/li><li>Leave the privileges radio button set to &#8220;Default privileges&#8221; <\/li><\/ul><ul><li>Click the\u00a0<strong>Add<\/strong>\u00a0button. <\/li><\/ul><\/li><\/ol>\n\n\n\n<p>This<strong> staff<\/strong>&nbsp;group (known as&nbsp;<strong>gpr_csurs_natsci_RStorGroup_staff<\/strong>&nbsp;in Active Directory) has now been created and you have added Homer Simpson as a member of this group.\u202f\u202f\u202fRepeat step 6 to add additional members to the Staff group.&nbsp;<\/p>\n\n\n\n<p>**Please note, creating groups in Grouper may take 60 minutes to replicate to Active Directory**\u202f&nbsp;<\/p>\n\n\n\n<p>Let\u2019s adjust the RStor&nbsp;folder permissions for this new group.&nbsp; First we need to give the members of the staff group access to  your RStorGroup folder so they can get a directory listing.&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Within Windows Explorer, navigate to your mapped <strong>RStor<\/strong>&nbsp;folder.<\/li><li>Right-click the <strong>RStorGroup<\/strong> folder, choose&nbsp;<strong>Properties<\/strong>&nbsp;and go to the&nbsp;<strong>Security<\/strong>&nbsp;tab.<\/li><li>Click the&nbsp;<strong>Edit<\/strong>&nbsp;button to open the Permissions dialog.<\/li><li>Click the&nbsp;<strong>Add<\/strong>&nbsp;button and type&nbsp;<strong>COLOSTATE\\gpr_csurs_natsci_<\/strong> <strong>RStorGroup_staff<\/strong>&nbsp;in the object names field.<\/li><li>Click&nbsp;<strong>OK&nbsp;<\/strong>to return to the Permissions dialog.<\/li><li>Choose the following three permissions for the staff group you just  added (These permissions will give the Staff group the ability to  navigate into your RStorGroup folder and act just like a member of the normal &#8220;members&#8221; group can) :\u202f\u202f&nbsp; <ul><li>Modify<\/li><li>Read &amp; Execute\u202f&nbsp;<\/li><li>List folder contents\u202f&nbsp;<\/li><li>Read <\/li><\/ul><\/li><li>Click&nbsp;<strong>OK<\/strong>&nbsp;to close the Permissions dialog.<\/li><li>Click&nbsp;<strong>OK&nbsp;<\/strong>to close the RStorGroup properties dialog.  Now give the staff group the ability to add\/remove files\/folders in the Staff folder, while removing the members group from their access.<\/li><li>Right-click the&nbsp;<strong>Staff<\/strong>&nbsp;folder and choose&nbsp;<strong>Properties<\/strong><\/li><li>Click on the&nbsp;<strong>Security<\/strong>&nbsp;tab and select the&nbsp;<strong>gpr_csurs_natsci_RStorGroup_staff<\/strong>&nbsp;group in the list.<\/li><li>Verify the &#8220;modify&#8221; permissions are still set.<\/li><li> Now, click the&nbsp;<strong>Advanced<\/strong>&nbsp;button to open the Advanced Security Settings dialog. <\/li><li>Click the&nbsp;<strong>Disable inheritance<\/strong>&nbsp;button and choose to&nbsp;<strong>Convert inherited permissions into explicit permissions on this object<\/strong>. <\/li><li>Now, click on the &#8216;edit&#8217; button and then choose the  <strong>gpr_csurs_natsci_RStorGroup_members<\/strong> group from the list.  You will now click on the <strong>Remove&nbsp;<\/strong>button.<\/li><li>Now we want to restrict access to the Private folder to just the admins. Right-click the&nbsp;<strong>Private<\/strong>&nbsp;folder and choose&nbsp;<strong>Properties<\/strong><\/li><li>Click on the&nbsp;<strong>Security<\/strong>&nbsp;tab and then click the&nbsp;<strong>Advanced<\/strong>&nbsp;button to open the Advanced Security Settings dialog.<\/li><li>Click the&nbsp;<strong>Disable inheritance<\/strong>&nbsp;button and choose to&nbsp;<strong>Convert inherited permissions into explicit permissions on this object<\/strong>. <ul><li>Select&nbsp;<strong>gpr_csurs_natsci_RStorGroup_staff<\/strong>&nbsp;group in the entries list and click the&nbsp;<strong>Remove&nbsp;<\/strong>button.<\/li><li>Select&nbsp;<strong>gpr_csurs_natsci_RStorGroup_members<\/strong> group in the entries list and click the&nbsp;<strong>Remove&nbsp;<\/strong>button. <\/li><li>This will prevent the staff and members group from accessing files\/folders within this Private folder.\u202f <\/li><\/ul><\/li><li>Click&nbsp;<strong>OK<\/strong>&nbsp;to close the Advanced Security Settings dialog.<\/li><li>Click&nbsp;<strong>OK<\/strong>&nbsp;to close the folder properties dialog.\u202f&nbsp;<\/li><\/ol>\n\n\n\n<p>&nbsp;If you have any questions or need help with these steps, please contact us with a ticket at <a href=\"https:\/\/cnsit.colostate.edu\/help\">https:\/\/cnsit.natsci.colostate.edu<\/a><\/p>\n\n\n\n<p>*Content for this article adopted from WCNR content found here: <a href=\"https:\/\/warnercnr.colostate.edu\/it\/network-data-storage\/csu-rstor-instructions-for-wcnr-users\">https:\/\/warnercnr.colostate.edu\/it\/network-data-storage\/csu-rstor-instructions-for-wcnr-users<\/a> *<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Below are instructions for configuring RStor to provide access to others within CNS or at CSU. Please substitute your RStor&nbsp;folder\/Group name everywhere you see \u201cRStorGroup.\u201d\u202f&nbsp;\u202f&nbsp; At first, only the original owners and members you have access to this folder. These were set in place when your RStor account and Group Share was created.\u202f Should you [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3072,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,6,13,14],"tags":[],"class_list":["post-3071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general-cnsit","category-knowledge-base","category-the-cloud","category-tips-and-tricks"],"_links":{"self":[{"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/posts\/3071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/comments?post=3071"}],"version-history":[{"count":4,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/posts\/3071\/revisions"}],"predecessor-version":[{"id":4433,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/posts\/3071\/revisions\/4433"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/media\/3072"}],"wp:attachment":[{"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/media?parent=3071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/categories?post=3071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/tags?post=3071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}