Samba implements the SMB protocol that Windows uses for network file sharing, which lets a Linux server offer shared folders that Windows, macOS and Linux clients open like any other network drive. In this tutorial you will install Samba on Ubuntu 24.04, create a shared folder for a group of users plus a private home share for each user, add a recycle bin, and connect from all three client operating systems.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS, for example a CubePath VPS or a machine on your local network, with enough disk space for the files you plan to store.
  • A non-root user with sudo privileges and UFW enabled with SSH allowed.
  • The network your clients connect from, for example your office LAN (192.168.1.0/24) or a VPN subnet (10.8.0.0/24).

Step 1 - Installing Samba

Install the Samba server and the smbclient command-line client, which you will use to test the shares from the server itself:

sudo apt update
sudo apt install samba smbclient

Check the version and that the file-sharing daemon smbd is running:

smbd --version
systemctl status smbd --no-pager
Version 4.19.5-Ubuntu
...
     Active: active (running)

Step 2 - Creating the users and group

Samba maps every connection to a Linux user, but it keeps its own password database, separate from the system passwords. The usual approach is to create Linux accounts that cannot log in over SSH, and give them a Samba password.

Create a group for everyone who may use the shared folder:

sudo groupadd sambausers

Create a user named alice with no login shell and add her to the group. Repeat for each person, replacing the name:

sudo adduser --disabled-password --gecos "" --shell /usr/sbin/nologin alice
sudo usermod -aG sambausers alice

Set the Samba password for the user. This is the password she will type when connecting from her computer:

sudo smbpasswd -a alice
New SMB password:
Retype new SMB password:
Added user alice.

List the users Samba knows about:

sudo pdbedit -L
alice:1001:

Step 3 - Creating the shared directory

Create the directory for the team share under /srv, the standard location for data served by the system:

sudo mkdir -p /srv/samba/shared
sudo chown root:sambausers /srv/samba/shared
sudo chmod 2770 /srv/samba/shared

Mode 2770 gives full access to the owner and the sambausers group and nothing to anyone else. The leading 2 is the setgid bit: files created inside inherit the sambausers group, so every member can edit files created by the others.

Verify the permissions:

ls -ld /srv/samba/shared
drwxrws--- 2 root sambausers 4096 Sep 25 10:00 /srv/samba/shared

Step 4 - Configuring the shares

Samba's configuration lives in /etc/samba/smb.conf. Back it up first:

sudo cp /etc/samba/smb.conf /etc/samba/smb.conf.bak

Open the file:

sudo nano /etc/samba/smb.conf

The Ubuntu defaults in the [global] section are sensible: SMB1 is disabled, and users authenticate with their Samba password. Add these lines at the end of the [global] section, just before the [homes] or [printers] sections:

   # Refuse old protocol versions; SMB 3 is supported by Windows 8 and later
   server min protocol = SMB3
   # Don't allow guest access to any share
   map to guest = never
   # Encrypt traffic with clients that support it
   smb encrypt = desired

Ubuntu's file contains a commented-out [homes] example. Scroll to the end of the file and add these two shares:

[homes]
   comment = Home directory
   browseable = no
   read only = no
   valid users = %S
   create mask = 0600
   directory mask = 0700

[shared]
   comment = Team files
   path = /srv/samba/shared
   browseable = yes
   read only = no
   valid users = @sambausers
   force group = sambausers
   create mask = 0660
   directory mask = 2770
   vfs objects = recycle
   recycle:repository = .recycle
   recycle:keeptree = yes
   recycle:versions = yes
   recycle:touch_mtime = yes

What each share does:

  • [homes] is a special share: each user who connects sees a share with their own username that points to their Linux home directory. valid users = %S ensures only that user can open it.
  • [shared] is available to members of sambausers (the @ means "group"). force group and the masks keep new files group-writable, matching the permissions from Step 3.
  • The recycle module moves deleted files into a hidden .recycle folder inside the share instead of deleting them, so accidental deletions can be recovered.

Check the configuration for errors:

testparm -s
Load smb config files from /etc/samba/smb.conf
Loaded services file OK.
...
[shared]
	comment = Team files
	path = /srv/samba/shared
...

If testparm reports Unknown parameter, fix the typo before continuing. Apply the changes:

sudo systemctl restart smbd

Step 5 - Testing the shares locally

Before touching the firewall, check that the shares work from the server itself. List the shares visible to alice:

smbclient -L localhost -U alice
Password for [WORKGROUP\alice]:

	Sharename       Type      Comment
	---------       ----      -------
	shared          Disk      Team files
	IPC$            IPC       IPC Service (ubuntu server (Samba, Ubuntu))
	alice           Disk      Home directory

Upload a file to the team share to confirm write access:

echo "hello from samba" > /tmp/test.txt
smbclient //localhost/shared -U alice -c 'put /tmp/test.txt test.txt; ls'
putting file /tmp/test.txt as \test.txt (0.9 kb/s) (average 0.9 kb/s)
  .                                   D        0  Thu Sep 25 10:05:12 2026
  ..                                  D        0  Thu Sep 25 10:00:03 2026
  test.txt                            A       17  Thu Sep 25 10:05:12 2026

On the server, the file belongs to alice and the sambausers group:

ls -l /srv/samba/shared
-rw-rw---- 1 alice sambausers 17 Sep 25 10:05 test.txt

Step 6 - Opening the firewall

Samba registers a UFW application profile named Samba. Allow it only from your client network, replacing the subnet with yours:

sudo ufw allow from 192.168.1.0/24 to any app Samba

Verify the rule:

sudo ufw status
To                         Action      From
--                         ------      ----
OpenSSH                    ALLOW       Anywhere
Samba                      ALLOW       192.168.1.0/24

Modern clients only need TCP 445. The profile also opens the legacy NetBIOS ports (137-139), which you can leave closed on a VPN by allowing only sudo ufw allow from 10.8.0.0/24 to any port 445 proto tcp instead.

Step 7 - Connecting from clients

In the examples below, replace your_server_ip with the server's LAN or VPN address.

Windows

Open File Explorer, type \\your_server_ip\shared in the address bar and sign in with alice and her Samba password. To keep it as a drive letter, right-click This PC, choose Map network drive, and enter the same path. From a terminal you can do the same with:

net use Z: \\your_server_ip\shared /user:alice /persistent:yes

macOS

In Finder, press Cmd+K, enter smb://your_server_ip/shared and click Connect. Choose Registered User and enter the credentials.

Linux

Install the CIFS utilities and create a mount point:

sudo apt install cifs-utils
sudo mkdir -p /mnt/shared

Store the credentials in a file only root can read, so the password is not visible in the process list or in /etc/fstab:

sudo nano /root/.smbcredentials
username=alice
password=alice_samba_password
sudo chmod 600 /root/.smbcredentials

Mount the share, making your local user the owner of the files:

sudo mount -t cifs //your_server_ip/shared /mnt/shared -o credentials=/root/.smbcredentials,uid=$(id -u),gid=$(id -g)

Check that it works:

ls -l /mnt/shared
-rwxr-xr-x 1 your_user your_user 17 Sep 25 10:05 test.txt

To mount it at boot, add a line to /etc/fstab, replacing 1000 with your user's UID and GID:

//your_server_ip/shared  /mnt/shared  cifs  credentials=/root/.smbcredentials,uid=1000,gid=1000,_netdev,nofail  0  0

The _netdev and nofail options wait for the network and prevent the boot from hanging if the server is unreachable. Test the entry with sudo mount -a.

Recovering deleted files

When a user deletes a file from [shared], the recycle module moves it to /srv/samba/shared/.recycle/<username>/, keeping the original folder structure. To restore one, move it back:

sudo mv /srv/samba/shared/.recycle/alice/report.docx /srv/samba/shared/

The recycle bin grows forever unless you empty it. A daily cron job that removes files older than 30 days is enough for most teams:

echo '30 3 * * * root find /srv/samba/shared/.recycle -type f -mtime +30 -delete' | sudo tee /etc/cron.d/samba-recycle

recycle:touch_mtime = yes in the share sets a file's modification time when it is deleted, which is why -mtime +30 counts from the deletion date rather than from the last edit.

Troubleshooting

  • NT_STATUS_LOGON_FAILURE. The Samba password is wrong or the user was never added with smbpasswd -a. Check with sudo pdbedit -L and reset it with sudo smbpasswd alice.
  • NT_STATUS_ACCESS_DENIED when opening or writing. The user is not in sambausers (check with id alice) or the directory permissions differ from Step 3. Group changes apply to new connections, so disconnect and reconnect the client.
  • Windows cannot reach the server at all. Test from the client with Test-NetConnection your_server_ip -Port 445 in PowerShell. If it fails, check the UFW rule and that the client's IP is inside the allowed subnet.
  • Older devices (scanners, NAS, Windows 7) cannot connect. They only speak SMB1 or SMB2. Lower server min protocol to SMB2_10 for Windows 7; avoid re-enabling SMB1.
  • Logs. Per-client logs are in /var/log/samba/. Raise the detail temporarily with log level = 3 in [global], and set it back once you have found the problem.

Conclusion

You now have a Samba file server on Ubuntu 24.04 with a group-writable team share, private home shares, a recycle bin and access restricted to your network. Next, plan backups of /srv/samba and the home directories (for example with restic or rsync to another server), add read-only shares for documents that should not be edited, and consider putting clients behind a WireGuard VPN if they work remotely.