Showing posts with label Domain Local. Show all posts
Showing posts with label Domain Local. Show all posts

Sunday, October 16, 2011

Implementing Universal Groups

Use Global Group to hold accounts as members. Avoid group nesting to the minimum to avoid confusion
Use Domain Local Groups to provide access to resources in specific domain then make domain local groups members of access control list for specific resources in the domain, such as share folders & printers
Use Universal Groups to provide extensive access to resources, particularly when Active Directory contains trees and forest, or to simplify access when there are multiple domains

Security Group Management

Types of groups and associated scopes:
Local: Stand-alone servers that are not part of any domain
Domain local: Used when there is a single domain or to manage resources in a particular domain so that global and universal groups can access those resources
Global: Used to manage group accounts from the same domain so that those accounts can access resources in the same and in other domains
Universal: Used to provide access to resources in any domain within the forest.
Security groups
Enable access to resources on a) a stand-alone server or b) in Active Directory
Distribution groups
Used for e-mail or telephone lists to provide a quick, mass distribution of information