Re: Managing Security Groups as Distribution Lists



It might be easier if you just gave everyone administrative access to
everything, then you wouldn't have to worry about setting any permissions at
all. Seriously though, you want to have some type of centralized control of
permissions. Using distribution groups as controlling points isn't
something to me that sounds very good.

Can't you delegate a small group of users the management of these groups and
allow them to manage the security groups. Once you start the whole sale
provision of others to manage there own permissions they start doing crazy
and stupid things and you are left with going back and fixing them. This is
going to take a lot more time than just setting up the permissions.

We do something very similar to what you do but our help desk/work station
support has manage group membership on these groups after we create them and
provide permissions to the files and folders.

Use security groups for security and use distribution groups for
distribution.

--


Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.


"Nir B" <nir@xxxxxxxxxxxxx> wrote in message
news:%23AAZ1rF4FHA.2196@xxxxxxxxxxxxxxxxxxxxxxx
> Hi All,
>
> We have Active Directory (Windows 2000)
> Each folder on my file server have folder owner and 3 corresponded groups
> (Group Scope = Global, Group type = Security):
> Folder Name Read Only
> Folder Name Read Write
> Folder Name Read Write Delete
>
> When user want permission to specific folder he call the HD and the HD is
> checking with the owner of the folder what permission to give him, and add
> him to the appropriate groups.
> I want to reduce the overhead and move the all workflow to the owner
> responsibility.
> I thought to do the following:
> -Add these groups E-Mail Address (do be available as DL)
> - set the folder owner as the owner of his corresponded groups
> - Learn the owner how to modify members via the Outlook
>
> What thinks I need to take into account in such configuration?
> Is there better way / product to move the all management cycle to the
> folder owner?
>
> Thanks,
>
> Nir
>
>
>
>


.



Relevant Pages

  • Re: Folder Permissions.
    ... With this createed security groups you set NTFS/share permissions on the folders where your files are located, ... Security groups can create 'conflicts' if some user accunts are members of multiple security groups that are used with concurrent permissions on your data folders/shares. ... If this is clear and your folder permission are not really to understand for you, i would create a new folder structure on a new shared fodler and copy data to the new structure where the permissions set as needed in the company, which is now done with your own created new security groups. ... More or less the same way you can use to built a new OU structure with new GPOs and move the users/computers to them, of course you have to test all new structures before with test accounts. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Dont Administrators have access to everything?
    ... folder, which the Limited users getaccess to. ... One of the Administrators is the Owner of nearly every ... the few that can be opened, but I thought the Administrators ... If you're an admin and you take ownership, and you replace permissions, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Lets talk about ownership!
    ... They will have the same permissions but the permissions are meaningless as there is no user to match. ... According my previous example the user "Terry" has read/write permissions on folder NickData. ... Ownership doesn't really matter as long as you have permissions. ... XP can be configured in Local Security Policy to make the Admin group the owner for files created by admins. ...
    (microsoft.public.windowsxp.general)
  • Re: Minimum NTFS Permissions - Theres such a thing???
    ... ?2001 Microsoft Corporation. ... HOW TO: Set Minimum NTFS Permissions Required for IIS 5.0 to Work WGID:198 ... " List Folder Contents" ...
    (microsoft.public.inetserver.iis.security)
  • Re: Unable to delete orphaned 1.5 GB System Restore folder
    ... The fact that the tech support is based in India has nothing to do with the ... If so you may want to leave this folder alone. ... down to all children folders because i can set those permissions to ... try deleting from the command line using system by using the AT ...
    (microsoft.public.windowsxp.security_admin)

Loading