Insights /Windows Server and file permissions

A file share works by IP address but fails by server name: where is the problem usually located?

When IP access works but name access fails, investigate DNS suffixes, A/AAAA records, stale caches, hosts overrides, SPNs, and names resolving to the wrong address.

Quick answer

When IP access works but name access fails, investigate DNS suffixes, A/AAAA records, stale caches, hosts overrides, SPNs, and names resolving to the wrong address. For this case, first verify DNS A/AAAA and short names, FQDNs and DNS suffixes, then use hosts file and DNS cache to decide whether remediation is needed.

Define the failure boundary first

For this file access and permissions case, establish the failure boundary with DNS A/AAAA and short names, FQDNs and DNS suffixes, then continue to hosts DNS. Capture the current state, incident time and one known-good comparison before changing production configuration.

Work through the dependency chain

CheckWhy it mattersRecommended action
01 · DNS A/AAAAVerify DNS A/AAAA on the affected path using logs, counters or state information rather than relying only on the configured rule.Record the current value, evidence source and timestamp for DNS A/AAAA. If adjustment is required, change one condition only and retain the original setting for rollback.
02 · short names, FQDNs and DNS suffixesVerify short names, FQDNs and DNS suffixes on the affected path using logs, counters or state information rather than relying only on the configured rule.Check short names, FQDNs and DNS suffixes read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
03 · hosts file and DNS cacheVerify hosts file and DNS cache on the affected path using logs, counters or state information rather than relying only on the configured rule.Compare hosts file and DNS cache with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.
04 · SPN/Kerberos authenticationReview the current state, related logs and recent changes for SPN/Kerberos authentication, then align them with the incident timeline before deciding whether a change is required.Record the current value, evidence source and timestamp for SPN/Kerberos authentication. If adjustment is required, change one condition only and retain the original setting for rollback.
05 · DFS aliases and CNAME recordsReview the current state, related logs and recent changes for DFS aliases and CNAME records, then align them with the incident timeline before deciding whether a change is required.Check DFS aliases and CNAME records read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
06 · IPv6 preferenceReview the current state, related logs and recent changes for IPv6 preference, then align them with the incident timeline before deciding whether a change is required.Compare IPv6 preference with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.
Read-only examples
nslookup fileserver.corp.example
ipconfig /displaydns

Change only after the evidence is clear

  1. Start with read-only evidence. Check DNS A/AAAA and short names, FQDNs and DNS suffixes before changing configuration.
  2. If the first checks are normal, continue with hosts file and DNS cache and SPN/Kerberos authentication, keeping evidence tied to the incident time.
  3. Change configuration only when the evidence explains the symptom. For DFS aliases and CNAME records, preserve the original value and define the rollback trigger before adjustment.
  4. Validate IPv6 preference in a controlled scope before expanding to production users or traffic.

Validation and rollback

  • Validate the complete user or application workflow; do not stop at the single status of DNS A/AAAA.
  • Recheck DFS aliases and CNAME records and IPv6 preference after the change and confirm that no new bypass, permission expansion or secondary error has appeared.
  • Archive evidence from DNS A/AAAA through IPv6 preference, together with before/after configuration, business validation and the rollback point.

Common wrong turns

  • Changing DNS A/AAAA and short names, FQDNs and DNS suffixes at the same time, which makes the original cause impossible to prove.
  • Treating a normal result for hosts DNS as proof that SPN/Kerberos and the rest of the business path are healthy.
  • Leaving a temporary exception related to DFS/ CNAME or IPv6 in production without an owner, expiry time and rollback note.

Related questions

Where should I start with “A file share works by IP address but fails by server name: where is the problem usually located?”?

Start with DNS A/AAAA and short names, FQDNs and DNS suffixes; they establish the first useful troubleshooting boundary without changing production state.

What should be checked after the first layer looks normal?

Continue with hosts file and DNS cache and SPN/Kerberos authentication, then correlate the result with the incident time and the actual user or application path.

What should be retained after the change?

Keep evidence for DFS aliases and CNAME records and IPv6 preference, plus the original configuration, validation result, observation notes and rollback point.

PreviousAfter a domain password change, sign-in still reports an incorrect password or the old password appears to work: what should be checked?NextA shared folder keeps requesting a username and password even though the password is correct: why is access still denied?

Need an assessment based on your actual environment?