Re: global local security group question



> Now, should I create local groups in AD and assign the global group as a
> member of the local group and then assign the local group access to the
> directories on the file server?

This is the recommended best practice, but this is mainly for environments
whereby there's multiple domains. When AD was first released, I think that
the idea was there would be several domains --recent security discoveries,
and the evolution of AD have changed this design. Therefore, in single
domains there doesn't seem very much point in adding global to local and
permissions to local...

--
Paul Williams

http://www.msresource.net/
http://forums.msresource.net/


.



Relevant Pages

  • RE: Adding AD Account to NT Global
    ... > accounts from other domains while global group is used to be added in other ... The local group in NT is only accessible within the controllers and can't be ... I have already done some successful migrations from nt4 to w2k3 root domain. ...
    (microsoft.public.windows.server.migration)
  • Hi.
    ... Each global group belongs to one or more: ... the local group. ... rather than giving rights at the login level. ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
    (Security-Basics)
  • Re: Group Accounts
    ... And that a Domain Local group can only access resources in the ... Wouldn't this restrict the Global Group members from accessing ... > You can nest groups and when nesting Domain Local group can contain Domain ... >> not be able to access resources outwith the domain, ...
    (microsoft.public.windows.server.general)
  • Re: proper file security methods
    ... and if the global group serves no purpose other than ... to access this particular resource, ... group a member of the local group. ... > group a member of the local group and assign the local group access to the ...
    (microsoft.public.windows.server.active_directory)
  • Determine Global Group vs User in Local?
    ... This code enumerates all local group members (Win2K web ... member server in a Win2K domain). ... is a global group, ...
    (microsoft.public.dotnet.security)

Loading