Re: Managing Security Groups as Distribution Lists
- From: "Paul Bergson" <pbergson@xxxxxxxxxxxxxxxxx>
- Date: Thu, 3 Nov 2005 07:38:48 -0600
It might be easier if you just gave everyone administrative access to
everything, then you wouldn't have to worry about setting any permissions at
all. Seriously though, you want to have some type of centralized control of
permissions. Using distribution groups as controlling points isn't
something to me that sounds very good.
Can't you delegate a small group of users the management of these groups and
allow them to manage the security groups. Once you start the whole sale
provision of others to manage there own permissions they start doing crazy
and stupid things and you are left with going back and fixing them. This is
going to take a lot more time than just setting up the permissions.
We do something very similar to what you do but our help desk/work station
support has manage group membership on these groups after we create them and
provide permissions to the files and folders.
Use security groups for security and use distribution groups for
distribution.
--
Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA
This posting is provided "AS IS" with no warranties, and confers no rights.
"Nir B" <nir@xxxxxxxxxxxxx> wrote in message
news:%23AAZ1rF4FHA.2196@xxxxxxxxxxxxxxxxxxxxxxx
> Hi All,
>
> We have Active Directory (Windows 2000)
> Each folder on my file server have folder owner and 3 corresponded groups
> (Group Scope = Global, Group type = Security):
> Folder Name Read Only
> Folder Name Read Write
> Folder Name Read Write Delete
>
> When user want permission to specific folder he call the HD and the HD is
> checking with the owner of the folder what permission to give him, and add
> him to the appropriate groups.
> I want to reduce the overhead and move the all workflow to the owner
> responsibility.
> I thought to do the following:
> -Add these groups E-Mail Address (do be available as DL)
> - set the folder owner as the owner of his corresponded groups
> - Learn the owner how to modify members via the Outlook
>
> What thinks I need to take into account in such configuration?
> Is there better way / product to move the all management cycle to the
> folder owner?
>
> Thanks,
>
> Nir
>
>
>
>
.
- Follow-Ups:
- References:
- Managing Security Groups as Distribution Lists
- From: Nir B
- Managing Security Groups as Distribution Lists
- Prev by Date: Re: password reset
- Next by Date: Re: Can not find LOCAL SYSTEM count memberships DC
- Previous by thread: Managing Security Groups as Distribution Lists
- Next by thread: Re: Managing Security Groups as Distribution Lists
- Index(es):
Relevant Pages
|
Loading