Samba implements the SMB protocol used by Windows file sharing, so a Linux server can offer network folders that Windows, macOS and Linux machines open natively. In this tutorial you will install Samba on Ubuntu 24.04, create a shared folder that only members of a Linux group can access with their own passwords, restrict it to your network with UFW, and connect to it from each type of client.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS, for example a CubePath VPS.
  • A non-root user with sudo privileges.
  • The network your clients connect from, for example a private network or VPN. The examples use the server IP 10.0.0.10 and the client subnet 10.0.0.0/24.

Step 1 - Installing Samba

Install the Samba server package:

sudo apt update
sudo apt install samba

Check the installed version and that the file-sharing daemon smbd is running:

smbd --version
systemctl status smbd
Version 4.19.5-Ubuntu
● smbd.service - Samba SMB Daemon
     Loaded: loaded (/usr/lib/systemd/system/smbd.service; enabled; preset: enabled)
     Active: active (running) since Thu 2026-09-25 10:05:32 UTC; 20s ago

The package also starts nmbd, which provides NetBIOS name browsing. Modern clients connect by IP or DNS name and do not need it, so you can disable it and close one more service:

sudo systemctl disable --now nmbd

Step 2 - Creating the shared directory and group

Access to the share will be controlled by membership in a Linux group. Create a group called smbshare:

sudo groupadd smbshare

Create the directory, give the group ownership and set permissions:

sudo mkdir -p /srv/samba/shared
sudo chgrp smbshare /srv/samba/shared
sudo chmod 2770 /srv/samba/shared

Mode 2770 gives full access to the owner and the group and none to anyone else. The leading 2 is the setgid bit: files created inside inherit the smbshare group, so every member can open files created by other members.

Verify the result:

ls -ld /srv/samba/shared
drwxrws--- 2 root smbshare 4096 Sep 25 10:08 /srv/samba/shared

The s in the group permissions confirms the setgid bit.

Step 3 - Creating Samba users

Every Samba user must exist as a Linux user, but has a separate Samba password stored in Samba's own database. If the account is only used for file sharing, create it without a home directory or login shell. Replace sammy with the user's name:

sudo useradd -M -s /usr/sbin/nologin sammy
sudo usermod -aG smbshare sammy

Set the user's Samba password. You will be asked to type it twice:

sudo smbpasswd -a sammy
New SMB password:
Retype new SMB password:
Added user sammy.

To give an existing Linux user access, skip useradd and only run the usermod and smbpasswd -a commands. Repeat for every user who needs the share, then list the Samba users:

sudo pdbedit -L
sammy:1001:

Later, change a password with sudo smbpasswd sammy, disable an account with sudo smbpasswd -d sammy and remove it from Samba with sudo smbpasswd -x sammy.

Step 4 - Configuring the share

Samba's configuration lives in /etc/samba/smb.conf. Back it up first:

sudo cp /etc/samba/smb.conf /etc/samba/smb.conf.bak

Ubuntu's default file already contains sensible [global] settings, including map to guest = bad user and usershare allow guests = yes. The share you are about to add does not allow guests, but you can harden the global section too. Open the file:

sudo nano /etc/samba/smb.conf

In the [global] section, add these lines below workgroup = WORKGROUP:

   server min protocol = SMB2_10
   restrict anonymous = 2

server min protocol = SMB2_10 refuses SMB1 and the earliest SMB2 dialect; every supported Windows, macOS and Linux client speaks SMB 2.1 or newer. restrict anonymous = 2 stops anonymous users from listing shares and users.

Then go to the end of the file and add the share definition:

[shared]
   comment = Team shared folder
   path = /srv/samba/shared
   browseable = yes
   read only = no
   guest ok = no
   valid users = @smbshare
   force group = smbshare
   create mask = 0660
   directory mask = 2770

Each option does the following:

OptionEffect
[shared]Share name clients use, as in \\10.0.0.10\shared
pathDirectory on the server
read only = noAllows writes (Samba shares are read-only by default)
guest ok = noRequires a user name and password
valid users = @smbshareOnly members of the smbshare group can connect (@ means group)
force groupNew files and directories belong to smbshare
create mask / directory maskMaximum permissions for new files (0660) and directories (2770)

Save the file and check it for errors with testparm:

testparm -s
Load smb config files from /etc/samba/smb.conf
Loaded services file OK.
Weak crypto is allowed by GnuTLS (e.g. NTLM as a compatibility fallback)

Server role: ROLE_STANDALONE
...
[shared]
	comment = Team shared folder
	directory mask = 02770
	force group = smbshare
	path = /srv/samba/shared
	read only = No
	valid users = @smbshare

Loaded services file OK. means the syntax is valid. The Weak crypto line is informational. Apply the configuration by restarting Samba:

sudo systemctl restart smbd

Step 5 - Allowing Samba through the firewall

The samba package installs a UFW application profile named Samba. Allow it only from your client network:

sudo ufw allow from 10.0.0.0/24 to any app Samba
sudo ufw status
Status: active

To                         Action      From
--                         ------      ----
22/tcp                     ALLOW       Anywhere
Samba                      ALLOW       10.0.0.0/24

The profile opens the NetBIOS ports 137-139 and SMB port 445. If you prefer to open only what modern clients use, allow TCP 445 instead: sudo ufw allow from 10.0.0.0/24 to any port 445 proto tcp.

Step 6 - Testing the share from the server

Before involving another machine, connect locally with smbclient, a command-line SMB client:

sudo apt install smbclient
smbclient //localhost/shared -U sammy

Enter the Samba password. At the smb: \> prompt, create a directory, list the share and exit:

smb: \> mkdir test
smb: \> ls
  .                                   D        0  Thu Sep 25 10:15:02 2026
  ..                                  D        0  Thu Sep 25 10:08:44 2026
  test                                D        0  Thu Sep 25 10:15:02 2026
smb: \> exit

Check the result on disk:

ls -l /srv/samba/shared
drwxrws--- 2 sammy smbshare 4096 Sep 25 10:15 test

The directory belongs to sammy and the smbshare group with the permissions from directory mask, so the rest of the group can use it too.

Step 7 - Connecting from clients

Windows

Open File Explorer, type \\10.0.0.10\shared in the address bar and press Enter. Log in with the Samba user name and password. To keep the share as a drive letter, right-click This PC, choose Map network drive, pick a letter and enter the same path.

macOS

In Finder, choose Go > Connect to Server (Command+K), enter smb://10.0.0.10/shared and click Connect. Select Registered User and enter the Samba credentials.

Linux

Install the CIFS mount helper on the client and create a mount point:

sudo apt install cifs-utils
sudo mkdir -p /mnt/shared

Store the credentials in a file only root can read, so the password does not appear in /etc/fstab or your shell history:

sudo nano /root/.smbcredentials
username=sammy
password=your_samba_password
sudo chmod 600 /root/.smbcredentials

Add an /etc/fstab line that mounts the share at boot. uid and gid make the files appear as owned by your local user; replace 1000 with the output of id -u and id -g:

sudo nano /etc/fstab
//10.0.0.10/shared  /mnt/shared  cifs  credentials=/root/.smbcredentials,uid=1000,gid=1000,_netdev,nofail  0  0

Reload systemd, mount the share and check it:

sudo systemctl daemon-reload
sudo mount /mnt/shared
df -h /mnt/shared
Filesystem          Size  Used Avail Use% Mounted on
//10.0.0.10/shared   98G  1.3G   92G   2% /mnt/shared

Step 8 - Monitoring connections

smbstatus shows who is connected, which shares they use and which files they have open:

sudo smbstatus
Samba version 4.19.5-Ubuntu
PID     Username     Group        Machine                                   Protocol Version  Encryption           Signing
----------------------------------------------------------------------------------------------------------------------------------------
4211    sammy        sammy        10.0.0.20 (ipv4:10.0.0.20:50522)          SMB3_11           -                    partial(AES-128-GMAC)

Logs are written to /var/log/samba/, one file per client machine plus log.smbd for the daemon itself.

Troubleshooting

NT_STATUS_LOGON_FAILURE. The user does not exist in Samba's database or the password is wrong. Check with sudo pdbedit -L and reset the password with sudo smbpasswd sammy.

NT_STATUS_ACCESS_DENIED when connecting or writing. The user is not in the smbshare group, or the directory permissions were changed. Check with id sammy and ls -ld /srv/samba/shared. Group changes apply to new connections, so disconnect and reconnect the client.

NT_STATUS_BAD_NETWORK_NAME. The share name is wrong or its path does not exist. Run testparm -s and compare the section name and path.

Windows cannot connect but smbclient works locally. Port 445 is blocked between the client and the server. Check sudo ufw status on the server and make sure the client's IP is inside the allowed subnet.

Conclusion

You installed Samba on Ubuntu 24.04, created a group share at /srv/samba/shared that requires a password and keeps group permissions consistent, limited it to your network with UFW and connected from Windows, macOS and Linux. Next, you could add more shares with different groups, place /srv/samba on a dedicated data disk, or apply disk quotas so a single user cannot fill the share.