Re: Number of groups in AD

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Rytis (lietryti[nospamdeletethis)
Date: 10/04/04


Date: Mon, 4 Oct 2004 17:20:59 +0300

I am planning to use domain local groups mainly.
So, if I understood correctly, if I will have ~2000 domain local groups,
it`s not a big problem? :-)
I heard, that number of groups can affect DC performance, but I can`t find
any articles in MS site about that.
"Tomasz Onyszko" <T.Onyszko@w2k.pl> wrote in message
news:O6SFgohqEHA.3900@TK2MSFTNGP10.phx.gbl...
> Rytis wrote:
>> Hi,
>>
>
> What kind of groups are You planning to create - how many universal groups
> are You planning in Your design.
>
> I don't know Your bussiness needs but 4 groups for each user :) it's a
> lot.
>
> This number of groups can affect Your logon performance. You have to
> remember that each time the users log on the security token is created and
> the security token is combination of user's SID and the SID of every group
> this which this user belongs to. SO the logon process will take longer if
> user will be a member of many groups becous the security token creation
> process will take longer.
>
> This token is also sent via network to every computer which this users
> access so the size of the token can slighlty increase the number of data
> sent through network.
>
> This of course is true for security groups - distribution groups don't
> affect a token size.
>
> Remember that membership in Universal groups need to be replicated to
> every GC server and this will affect Your network traffic, so the number
> of Universal groups and users in universal group is mportant (try to avoid
> adding individual users to universal group - use group nesting). Queries
> to the GC from the domain controllers also can create additional traffic
> in Your network but WIndows 2003 universal group membership caching
> feature will help You minimize impact of this queries to Your network.
>
>
> --
> Tomasz Onyszko [MVP]
> T.Onyszko@w2k.pl
> http://www.w2k.pl



Relevant Pages

  • RE: Intraforest Migration
    ... And, When you restructure domains, you must migrate domain local groups ... Subject: Intraforest Migration ... convert all domain local and global groups to universal groups ...
    (microsoft.public.windows.server.migration)
  • Re: AD Migration and Domain local groups
    ... The permissions on the Source file server shares ... I understood that Domain Local groups could have membership from other ... trusted domains and that they don't have to be Universal Groups. ...
    (microsoft.public.windows.server.migration)
  • RE: restricted groups?
    ... use Universal Groups to do that. ... accounts from any domain in any forest. ... A global group can contain other global groups and accounts from the same ... other domain local groups from the same domain that the group belongs to. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Intraforest Migration
    ... Actually, to protect the scenario you mentioned, we should migrate the ... And, When you restructure domains, you must migrate domain local groups ... Subject: Intraforest Migration ... convert all domain local and global groups to universal groups ...
    (microsoft.public.windows.server.migration)
  • Re: Universal Distribution group in a Mixed Mode Domain
    ... Isn't it just a confusion using Universal Groups in Mixed Mode environment? ... >> The problem is that I am just taking over a Windows 2000 network and I ...
    (microsoft.public.win2000.security)