Group Accounts

From: Solar Nowhere (ihatespam_at_youwontgetme.com)
Date: 08/21/04


Date: Sat, 21 Aug 2004 18:20:40 +0100

Could someone please explain the logic/strategy in the following
group memberships...
I've read in MS Press that user accounts be placed in global groups
and then place the global group inside a domain local group. Permissions
are then assigned through the domain local group. In this theory, users will
not be able to access resources outwith the domain, as local groups can only
acees resources where the account was created. So wouldn;t it be better to
assign users to global groups so they can access resources outwith the
domain.
I know we can use Universal groups to simplify, but that would have to be in
native mode.

I know I'm missing a point somewhere along the line, hopefully someone can
make
this easier for me to understand the logic behind the group placements.

Thank You



Relevant Pages

  • RE: ntfs permissions and AD restore password
    ... I seem to be stuck which way to play the changes to the permissions after I ... If I simply change the domain local group to become a universal groups then ... -add the User Accounts to Global Groups ...
    (microsoft.public.windows.server.active_directory)
  • Re: Group Accounts
    ... You can nest groups and when nesting Domain Local group can contain Domain ... > I've read in MS Press that user accounts be placed in global groups ... > and then place the global group inside a domain local group. ... > not be able to access resources outwith the domain, ...
    (microsoft.public.windows.server.general)
  • Re: Global Group
    ... global groups to local groups. ... > global groups from each domain to a universal group and assign the> permissions to the universal group. ... Microsoft seem to have changed their> mind about the A-G-DL-P permissions model and don't recommend you assign> permissions directly to a domain local group. ...
    (microsoft.public.win2000.active_directory)
  • Re: External trust & resources sharing
    ... It's not clear the direction of trust. ... > But if I am trying to search for this domain local group from SQL server ... I can not found it - only global groups are listed. ... this sounds like you're not in native mode. ...
    (microsoft.public.windows.server.active_directory)
  • Global Group Info in Domain Local Group AD Query Help
    ... I am enumerating a Domain Local Group. ... as Global Groups from other domains. ... When checking membership of the ... I need to get the remote domain name and group name. ...
    (microsoft.public.dotnet.framework)