Re: AD Design Question

Tech-Archive recommends: Fix windows errors by optimizing your registry




"briant97" <briant97@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:38F05A1C-35D7-4132-96E7-0C480B38B728@xxxxxxxxxxxxxxxx
I have a question on the AD Design that I am working on.



Quick Overview
Domain.com
Home Office

HR

HR Users

HR Groups

HR Computers

IT

IT Users

IT Admins

IT Service Accounts

IT Groups

IT Computers



That is a basic structure I have been working with other departments
included. My question comes in with how should you handle misc. contacts
and
then misc groups.

THE KEY to OU Design is to create OUs that represent the way
you wish to do two things:

1) Delegate Authority (to junior or local admins)

2) Link Group Policy (including overriding GPOs at child levels)

OUs are not Groups, and Groups are almost totally unrelated to
Group Policy. (sounds wrong but it's true.)

For instance we have application groups that allows
certain users to use an online web application to post pictures to our
website. This group is called app_webmaintanence.

Groups are used primarily for granting access to resources. Users
can be put into MANY groups (Global usually) and these groups
can be put into (Local) groups for resource access.

Then comes the question
of handling outside contacts as well as contacts for our parent company.

Another item I have concerns about is placement misc distribution groups
and
so on and so forth. I guess items that really don't fall under any
specific
department within the company.

Think of GLOBAL groups for any relevant "set of people" and think of
LOCAL groups as representing a set of resources.


--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)


.



Relevant Pages

  • Re: object system...
    ... entropy either remains constant or declines. ... Nevertheless we do know how to create computers and how to write software ... Emulating life will never give us any ... We observe that the same tasks require more resources than ...
    (comp.object)
  • Re: Prevent users installing software
    ... user from accessing domain resources is credentials. ... had access to the file server. ... including domain computers via file and print sharing. ... to exisitng network resources also. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Add another domain user group to local administrators of all computers in an OU with removing ot
    ... But if you only work with groups in restricted groups, you can just add/remove user to the group in AD you specified. ... admins group. ... Create the gpo in the ou where the Computers reside, ... "Add another domain user or group to local administrators of all ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Rights
    ... Ordinary users didn't need local admins ... Create a new OU for computers. ... Delegate permissions create/delete ... Add IT_Techs to local administrators group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Renaming computer error
    ... this case meaning all mapped resources. ... The forward slash is correct. ... I went to my command prompt screen. ... >>> We have about 150 computers divided into three domains. ...
    (microsoft.public.windowsxp.network_web)