Well, when I taught MCSE classes, the general rule was that you use share permissions in a workgroup where central authentication wasn't available, or on systems that still ran FAT filesystems. Barring those unusual situations, you set the share to Everyone/Full Control and applied appropriate NTFS permissions.
Combining physical (NTFS) and logical (share) permissions can create an environment that's difficult to manage. The prior admin team at the organization that I support today never learned that, and the helpdesk regularly gets calls about people not having access and they can't figure out why - because the NTFS permissions are correct. We remove share restrictions and things work as expected.
Basically, you use one or the other, but not both in combination. NTFS provides higher security and more granularity, which is why it's the recommended option.
Glenn
_________________________
Actually I
am a Rocket Scientist!