How to create a temporary read-only NAS share
A network-attached storage device can make it easy to share photos, documents, videos, and project files with visitors, contractors, or members of a local network. However, giving someone access to a normal shared folder may allow accidental edits, deletions, or file renaming. A read-only share provides a safer way to distribute files while preserving the original data.
A temporary guest folder is especially useful when the recipient needs access for a limited period. You can publish training materials, event photos, media files, invoices, or reference documents without creating a permanent user account. The same approach works on popular NAS platforms, including Synology DSM and QNAP QTS, although the menu names differ slightly.
The key is to combine read-only permissions with a separate account or controlled link, a strong expiration policy, and a review of inherited access rules. A permission that looks correct at the shared-folder level can be undermined by a user group, an application, or a public link configured elsewhere.
Plan the guest access before changing permissions
Start by deciding what guests need to see and how they will connect. A dedicated shared folder is usually safer than exposing an existing folder containing private files. Copy or publish only the required material into this location, and remove metadata or documents that should not leave the organization.
Choose between account-based access and a file-sharing link. A guest account offers clearer identity tracking and can be disabled at any time. A secure share link is quicker for short-term distribution, but anyone who obtains the link may be able to open the files unless you add a password and expiration date.
Access duration should match the purpose of the share. An event folder might remain available for two weeks, while a contractor’s reference files may need access for a month. Write down the removal date so temporary access does not quietly become permanent.
Create a separate shared folder
In Synology DSM, open File Station or Control Panel and create a new shared folder under Shared Folder. In QNAP QTS, use Control Panel and Shared Folders to create a dedicated location. Give it a clear name such as Guest-Documents or Event-Media, avoiding names that reveal confidential projects or internal departments.
Enable encryption when the folder contains sensitive business information and the NAS model supports it. Encryption protects data at rest, but it does not replace account security or transport encryption. Use HTTPS for browser-based access and avoid exposing administrative services directly to the public internet.
Keep the folder outside personal home directories and private departmental shares. This simplifies permission management and makes it easier to audit what guests can access. If the NAS supports snapshots, consider enabling them for the folder so an administrator can recover files after an accidental change by an authorized internal user.
Apply read-only permissions correctly
Create a dedicated guest user or group rather than assigning permissions to an existing staff account. In the shared-folder permission panel, grant Read only access to the guest identity. Remove Write, Modify, Delete, and Administration rights. On some systems, permission options may be presented as read/write, read-only, or deny.
Check the effective permissions after saving the change. Synology and QNAP systems can apply permissions through multiple layers, including shared folders, subfolders, group membership, ACL entries, and application-specific settings. A guest account should not belong to a group that grants broader access to the same location.
Use the following settings as a practical baseline:
| Access area | Recommended setting | Reason |
|---|---|---|
| Shared folder | Read-only | Allows viewing and downloading without edits |
| Guest account | Standard user | Prevents administrative actions |
| Group membership | Dedicated guest group | Keeps permissions easy to audit |
| File-sharing link | Password protected | Reduces access if the URL is forwarded |
| Link expiration | Fixed end date | Removes access automatically |
| Network protocol | HTTPS or encrypted service | Protects credentials and file transfers |
| Administrative access | Disabled for guest | Prevents configuration changes |
Test both the intended behavior and the blocked behavior. Open the share using the guest account and confirm that files can be viewed or downloaded. Then try to upload a file, rename an item, move a folder, and delete a document. A proper read-only configuration should reject each write operation.
Choose a safe connection method
For guests on the same home or office network, a mapped network drive or File Station connection may be sufficient. SMB access can work well for Windows and macOS users, but it should be restricted to the local network or a trusted VPN. Do not expose SMB ports directly to the internet.
For remote access, use the NAS vendor’s secure sharing feature, a reverse proxy with HTTPS, or a VPN. Synology File Station and QNAP File Station can generate sharing links with passwords and expiration dates. Configure the link to allow viewing and downloading only, if the platform provides that option.
Disable features that permit uploads, comments, editing, or synchronization unless guests genuinely need them. Some collaboration tools create their own permissions and may ignore the expectations set on a standard shared folder. Review the settings of the application delivering the files, rather than relying only on the underlying NAS ACL.
A public link should be treated as a credential. Send the URL and password through separate channels, avoid posting them together in a public chat, and revoke the link when the distribution period ends. If the files are particularly sensitive, use named accounts instead of anonymous links.
Secure the NAS and guest account
Use a unique password for each guest identity, with a minimum length that meets your organization’s policy. If several people need access, a group can simplify permissions, but individual accounts provide better audit records. Avoid sharing an administrator account or using the default admin profile.
Enable multi-factor authentication for administrators and staff accounts. Guest MFA may not be practical for a short event, but any account with access to business or personal data should use an additional verification method where supported. Activate account lockout or login protection to reduce password-guessing attempts.
Keep DSM, QTS, packages, and NAS applications updated. Security fixes may affect the web interface, VPN service, file-sharing tools, or media server. Disable unused services such as FTP, Telnet, legacy SMB versions, and remote administration from the public internet.
Firewall rules should limit access to the smallest practical set of networks. A local-only share should accept connections from the home or office subnet. A remote share should use a VPN, trusted IP ranges, or a secure gateway when possible. Automatic router port mapping can expose services unexpectedly, so review UPnP and firewall changes after setup.
Verify, monitor, and remove access
Before sending the link or account details, perform a complete guest test from a separate browser profile, computer, or mobile device. Confirm that the guest cannot browse other shared folders, view private directory names, or access NAS management pages. Browser sessions can retain administrator cookies, so a clean session is important.
Review connection logs and file-access records when the NAS supports them. These records can show login times, source addresses, downloads, and failed authentication attempts. Enable auditing selectively if the NAS has limited storage or processing capacity, and retain logs according to your privacy and compliance requirements.
At the scheduled end date, disable the guest account, revoke the share link, and remove the dedicated folder if it is no longer needed. Delete obsolete copies from recycle bins, snapshots, synchronization targets, and backup staging locations when policy allows. If the files must be retained, move them to an internal archive with separate permissions.
After removal, test the old link or credentials to verify that access has actually stopped. Also check whether a downloaded copy remains outside the NAS. Read-only access prevents changes to the source files, but it cannot prevent recipients from saving, copying, or photographing content that they are allowed to view.
Practical recommendations for temporary sharing
- Create a dedicated guest folder containing only the files intended for distribution.
- Use a standard guest account or protected link with read-only permissions and a fixed expiration date.
- Keep SMB and administrative interfaces off the public internet; use HTTPS or a VPN for remote access.
- Test viewing, downloading, uploading, renaming, and deleting from a clean guest session.
- Revoke accounts and links promptly, then review logs, snapshots, recycle bins, and backup copies.
A well-configured read-only share gives guests convenient access without turning a temporary request into a permanent security risk. Set up the dedicated folder, verify the effective permissions, protect the connection, and record the date when access must end. Then use the NAS audit logs and a clean test account to confirm that the shared files remain available only to the intended audience.