Samba implements the SMB protocol that Windows uses for network file sharing, which lets a Linux server offer shared folders that Windows, macOS and Linux clients open like any other network drive. In this tutorial you will install Samba on Ubuntu 24.04, create a shared folder for a group of users plus a private home share for each user, add a recycle bin, and connect from all three client operating systems.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS, for example a CubePath VPS or a machine on your local network, with enough disk space for the files you plan to store.
- A non-root user with
sudoprivileges and UFW enabled with SSH allowed. - The network your clients connect from, for example your office LAN (
192.168.1.0/24) or a VPN subnet (10.8.0.0/24).
WarningNever expose SMB (TCP port 445) to the whole internet. It is one of the most scanned and attacked ports. If your server is in a data center, give clients access through a VPN such as WireGuard and allow Samba only from the VPN subnet, as shown in Step 6.
Step 1 - Installing Samba
Install the Samba server and the smbclient command-line client, which you will use to test the shares from the server itself:
sudo apt update
sudo apt install samba smbclient
Check the version and that the file-sharing daemon smbd is running:
smbd --version
systemctl status smbd --no-pager
Version 4.19.5-Ubuntu
...
Active: active (running)
Step 2 - Creating the users and group
Samba maps every connection to a Linux user, but it keeps its own password database, separate from the system passwords. The usual approach is to create Linux accounts that cannot log in over SSH, and give them a Samba password.
Create a group for everyone who may use the shared folder:
sudo groupadd sambausers
Create a user named alice with no login shell and add her to the group. Repeat for each person, replacing the name:
sudo adduser --disabled-password --gecos "" --shell /usr/sbin/nologin alice
sudo usermod -aG sambausers alice
Set the Samba password for the user. This is the password she will type when connecting from her computer:
sudo smbpasswd -a alice
New SMB password:
Retype new SMB password:
Added user alice.
List the users Samba knows about:
sudo pdbedit -L
alice:1001:
Step 3 - Creating the shared directory
Create the directory for the team share under /srv, the standard location for data served by the system:
sudo mkdir -p /srv/samba/shared
sudo chown root:sambausers /srv/samba/shared
sudo chmod 2770 /srv/samba/shared
Mode 2770 gives full access to the owner and the sambausers group and nothing to anyone else. The leading 2 is the setgid bit: files created inside inherit the sambausers group, so every member can edit files created by the others.
Verify the permissions:
ls -ld /srv/samba/shared
drwxrws--- 2 root sambausers 4096 Sep 25 10:00 /srv/samba/shared
Step 4 - Configuring the shares
Samba's configuration lives in /etc/samba/smb.conf. Back it up first:
sudo cp /etc/samba/smb.conf /etc/samba/smb.conf.bak
Open the file:
sudo nano /etc/samba/smb.conf
The Ubuntu defaults in the [global] section are sensible: SMB1 is disabled, and users authenticate with their Samba password. Add these lines at the end of the [global] section, just before the [homes] or [printers] sections:
# Refuse old protocol versions; SMB 3 is supported by Windows 8 and later
server min protocol = SMB3
# Don't allow guest access to any share
map to guest = never
# Encrypt traffic with clients that support it
smb encrypt = desired
Ubuntu's file contains a commented-out [homes] example. Scroll to the end of the file and add these two shares:
[homes]
comment = Home directory
browseable = no
read only = no
valid users = %S
create mask = 0600
directory mask = 0700
[shared]
comment = Team files
path = /srv/samba/shared
browseable = yes
read only = no
valid users = @sambausers
force group = sambausers
create mask = 0660
directory mask = 2770
vfs objects = recycle
recycle:repository = .recycle
recycle:keeptree = yes
recycle:versions = yes
recycle:touch_mtime = yes
What each share does:
[homes]is a special share: each user who connects sees a share with their own username that points to their Linux home directory.valid users = %Sensures only that user can open it.[shared]is available to members ofsambausers(the@means "group").force groupand the masks keep new files group-writable, matching the permissions from Step 3.- The
recyclemodule moves deleted files into a hidden.recyclefolder inside the share instead of deleting them, so accidental deletions can be recovered.
Check the configuration for errors:
testparm -s
Load smb config files from /etc/samba/smb.conf
Loaded services file OK.
...
[shared]
comment = Team files
path = /srv/samba/shared
...
If testparm reports Unknown parameter, fix the typo before continuing. Apply the changes:
sudo systemctl restart smbd
Step 5 - Testing the shares locally
Before touching the firewall, check that the shares work from the server itself. List the shares visible to alice:
smbclient -L localhost -U alice
Password for [WORKGROUP\alice]:
Sharename Type Comment
--------- ---- -------
shared Disk Team files
IPC$ IPC IPC Service (ubuntu server (Samba, Ubuntu))
alice Disk Home directory
Upload a file to the team share to confirm write access:
echo "hello from samba" > /tmp/test.txt
smbclient //localhost/shared -U alice -c 'put /tmp/test.txt test.txt; ls'
putting file /tmp/test.txt as \test.txt (0.9 kb/s) (average 0.9 kb/s)
. D 0 Thu Sep 25 10:05:12 2026
.. D 0 Thu Sep 25 10:00:03 2026
test.txt A 17 Thu Sep 25 10:05:12 2026
On the server, the file belongs to alice and the sambausers group:
ls -l /srv/samba/shared
-rw-rw---- 1 alice sambausers 17 Sep 25 10:05 test.txt
Step 6 - Opening the firewall
Samba registers a UFW application profile named Samba. Allow it only from your client network, replacing the subnet with yours:
sudo ufw allow from 192.168.1.0/24 to any app Samba
Verify the rule:
sudo ufw status
To Action From
-- ------ ----
OpenSSH ALLOW Anywhere
Samba ALLOW 192.168.1.0/24
Modern clients only need TCP 445. The profile also opens the legacy NetBIOS ports (137-139), which you can leave closed on a VPN by allowing only sudo ufw allow from 10.8.0.0/24 to any port 445 proto tcp instead.
Step 7 - Connecting from clients
In the examples below, replace your_server_ip with the server's LAN or VPN address.
Windows
Open File Explorer, type \\your_server_ip\shared in the address bar and sign in with alice and her Samba password. To keep it as a drive letter, right-click This PC, choose Map network drive, and enter the same path. From a terminal you can do the same with:
net use Z: \\your_server_ip\shared /user:alice /persistent:yes
macOS
In Finder, press Cmd+K, enter smb://your_server_ip/shared and click Connect. Choose Registered User and enter the credentials.
Linux
Install the CIFS utilities and create a mount point:
sudo apt install cifs-utils
sudo mkdir -p /mnt/shared
Store the credentials in a file only root can read, so the password is not visible in the process list or in /etc/fstab:
sudo nano /root/.smbcredentials
username=alice
password=alice_samba_password
sudo chmod 600 /root/.smbcredentials
Mount the share, making your local user the owner of the files:
sudo mount -t cifs //your_server_ip/shared /mnt/shared -o credentials=/root/.smbcredentials,uid=$(id -u),gid=$(id -g)
Check that it works:
ls -l /mnt/shared
-rwxr-xr-x 1 your_user your_user 17 Sep 25 10:05 test.txt
To mount it at boot, add a line to /etc/fstab, replacing 1000 with your user's UID and GID:
//your_server_ip/shared /mnt/shared cifs credentials=/root/.smbcredentials,uid=1000,gid=1000,_netdev,nofail 0 0
The _netdev and nofail options wait for the network and prevent the boot from hanging if the server is unreachable. Test the entry with sudo mount -a.
Recovering deleted files
When a user deletes a file from [shared], the recycle module moves it to /srv/samba/shared/.recycle/<username>/, keeping the original folder structure. To restore one, move it back:
sudo mv /srv/samba/shared/.recycle/alice/report.docx /srv/samba/shared/
The recycle bin grows forever unless you empty it. A daily cron job that removes files older than 30 days is enough for most teams:
echo '30 3 * * * root find /srv/samba/shared/.recycle -type f -mtime +30 -delete' | sudo tee /etc/cron.d/samba-recycle
recycle:touch_mtime = yes in the share sets a file's modification time when it is deleted, which is why -mtime +30 counts from the deletion date rather than from the last edit.
Troubleshooting
NT_STATUS_LOGON_FAILURE. The Samba password is wrong or the user was never added withsmbpasswd -a. Check withsudo pdbedit -Land reset it withsudo smbpasswd alice.NT_STATUS_ACCESS_DENIEDwhen opening or writing. The user is not insambausers(check withid alice) or the directory permissions differ from Step 3. Group changes apply to new connections, so disconnect and reconnect the client.- Windows cannot reach the server at all. Test from the client with
Test-NetConnection your_server_ip -Port 445in PowerShell. If it fails, check the UFW rule and that the client's IP is inside the allowed subnet. - Older devices (scanners, NAS, Windows 7) cannot connect. They only speak SMB1 or SMB2. Lower
server min protocoltoSMB2_10for Windows 7; avoid re-enabling SMB1. - Logs. Per-client logs are in
/var/log/samba/. Raise the detail temporarily withlog level = 3in[global], and set it back once you have found the problem.
Conclusion
You now have a Samba file server on Ubuntu 24.04 with a group-writable team share, private home shares, a recycle bin and access restricted to your network. Next, plan backups of /srv/samba and the home directories (for example with restic or rsync to another server), add read-only shares for documents that should not be edited, and consider putting clients behind a WireGuard VPN if they work remotely.
