Most tech’s know that you can add a dollar sign ($) to the end of the name of a share and make it hidden but you can also have Windows show users ONLY the folders they have access to. I have this feature enabled with all my clients because it is hard to hack what you cannot see. It keeps the prying eyes of some staff from just wondering what is in that folder named PAYROLL or ACCOUNTING.
Access Based Enumeration is the feature that hides folders from users that do not have permission to that folder. Access based enumeration (ABE) came out in Windows 2008 and has remained unchanged since, because it just works.
How to Setup Access Based Enumeration:
- Launch SERVER MANAGER in Server 2012 or Server 2016
- Click on FILE AND STORAGE SERVICES
- Click on SHARES
- On EACH SHARE (one at a time), right click on the share and select PROPERTIES
- Expand SETTINGS
- Click ENABLE ACCESS BASED ENUMERATION
From this point on only users that have permissions to that folder/share will be able to see it.
More information on Access Based Enumeration can be found on the Microsoft Blog HERE.