Security Groups issue...



*** Note, I posted this is the "security" group, but someone suggested I put it here to get an answer. ***

One reason I ask, is because of this problem. I have two security groups, within my domain, and two servers in my domain. One server is a domain server (DOM), the other is a member server (MEM).
I have 2 security groups. The difference between the two is one is a DLS group, the other is a GS group. The DLS one doesn't allow the security group to be set on servers other than the domain servers. That is, if you are on DOM and you create a directory, you can grant it "Information Systems_DLS" security, or "Information Systems_GS" security. But if you log on to MEM, and try that it won't work. You need to grant it "Information Systems_GS". The option to grant any DLS doesn't even show up in the security selection on the member server.

I don't really grasp this. Should "Domain level Security" allow you to grant that security group to any member server?

I know how security groups work together, how certain ones can't be part of others, etc. But I don't really understand how they work, or where and when to use them.

Where are DLS (Domain Local Security) groups used, and why?
How about GS (Global Security) groups? Universal Security groups?

Is there any good documentation that explains how these are used and why?

Thanks for any info.
--
Bill Tkach
MSP, A+
visual{period}eyes{period}this{at}gmail{period}com
.



Relevant Pages

  • security-basics Digest of: get.123_145
    ... VPN to ASP a security risk? ... Re: Multiple IPSec tunnels? ... Subject: Security NT Server ... VPN to ASP a security risk? ...
    (Security-Basics)
  • << SBS News of the week - Sept 26 >>
    ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: << SBS News of the week - Sept 26 >>
    ... > And he points to the info you need to put the file on the server in the ... > at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... An attacker can exploit these flaws in tandem via specially ...
    (microsoft.public.backoffice.smallbiz2000)
  • << SBS News of the week - Sept 26 >>
    ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
    (microsoft.public.windows.server.sbs)
  • Re: << SBS News of the week - Sept 26 >>
    ... > And he points to the info you need to put the file on the server in the ... > at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... An attacker can exploit these flaws in tandem via specially ...
    (microsoft.public.windows.server.sbs)

Loading