Re: Distribution Lists



On May 9, 11:24 am, TSAM <T...@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
Hello all,

While creating a new group aka distribution list, we have Group Scope and
Group type. It's always confusing for me. Could somebody provide an advanced/
detailed description and scenarios where/ when to use them?

With Group Scope there is domain local, global and universal and with group
type there is security and distribution. What's the purpose of each of them.
Could all of these group with all possible combination receive email from
internal exchange servers and external email accounts.

Thanks



DISTRIBUTION GROUPS are used as just that, a place to distribute
emails to people. It is email enabled and has an address and when you
send an email to it it to goes to all of its members.

SECURITY GROUPS are used to protect resources, are not mail enabled
and should never be used as such.

In our situation, everywhere we use these in Active Directory you will
see a "-S" after the name if it is a security group. If you don't see
the "-S", it is a Distribution Group and should never be used to grant
or deny access to a resource, for numerous reasons:

A: ocassionally a person who is a member of a security group may not
be part of the same named distro group, or they may have different
access rights in the security group, using the distro group doesn't
carry any real permissions with it.

B: Using a distro group for security automatically converts it to a
security group, if you see this during an audit and convert it back to
a distro group, whatever it was securing is now hosed.


E



.



Relevant Pages

  • Re: Create a group name in Exchange
    ... Create either the mail enabled Distribution or Security Group in AD Users ... to apply permissions on objects: ... email distribution lists. ...
    (microsoft.public.exchange.admin)
  • RE: Groups X Distribution list - Permissions
    ... the difference between a security group and a distibution ... group is that a distribution group is used only for distribution you cannot ... when we are talking about permissions. ... > permissions for a resource account, if I add the user as an author on the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Restricting users from logging on to computers outside their OU
    ... putting all the users in the Distribution OU into one security group, ... One way to accomplish this would be specifying who can logon vs. ... Restricting users from logging on to computers outside their OU ... we have a Distribution OU which contains ...
    (microsoft.public.windows.group_policy)
  • Re: Create a group name in Exchange
    ... Create either the mail enabled Distribution or Security Group in AD Users ... This simplifies administration by allowing you to set permissions ... You can also use these groups as email distribution lists. ...
    (microsoft.public.exchange.admin)
  • Re: Cannot create a Universal Security Group in AD.
    ... To create Universal Security groups the AD domain has to be in Native ... > required to be a security group that grant permissions and be able to ... > I want to select Universal in Group Scope and Security in Group Type. ...
    (microsoft.public.exchange.admin)