Use Global Group to hold accounts as members. Avoid group nesting to the minimum to avoid confusion
Use Domain Local Groups to provide access to resources in specific domain then make domain local groups members of access control list for specific resources in the domain, such as share folders & printers
Use Universal Groups to provide extensive access to resources, particularly when Active Directory contains trees and forest, or to simplify access when there are multiple domains
Showing posts with label Universal. Show all posts
Showing posts with label Universal. Show all posts
Sunday, October 16, 2011
Security Group Management
Types of groups and associated scopes:
Local: Stand-alone servers that are not part of any domain
Domain local: Used when there is a single domain or to manage resources in a particular domain so that global and universal groups can access those resources
Global: Used to manage group accounts from the same domain so that those accounts can access resources in the same and in other domains
Universal: Used to provide access to resources in any domain within the forest.
Security groups
Enable access to resources on a) a stand-alone server or b) in Active Directory
Distribution groups
Used for e-mail or telephone lists to provide a quick, mass distribution of information
Local: Stand-alone servers that are not part of any domain
Domain local: Used when there is a single domain or to manage resources in a particular domain so that global and universal groups can access those resources
Global: Used to manage group accounts from the same domain so that those accounts can access resources in the same and in other domains
Universal: Used to provide access to resources in any domain within the forest.
Security groups
Enable access to resources on a) a stand-alone server or b) in Active Directory
Distribution groups
Used for e-mail or telephone lists to provide a quick, mass distribution of information
Subscribe to:
Posts (Atom)
