Re: Universal Groups
- From: "P" <p@xxxxx>
- Date: Wed, 27 Sep 2006 13:03:57 +0800
Okay.. this is a single domain spread over multiple sites to GC's at each
site.. so technically its not a problem but its still not a great idea..
I was wondering if long term local/global groups would dissapear and it
would just be a universal group world..
regards
paul
"Vincent Xu [MSFT]" <v-xuwen@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:5Dwltdd4GHA.1864@xxxxxxxxxxxxxxxxxxxxxxxx
Hi,
Two Points:
1. We use domain local group for security reason.Groups with domain local
scope help you define and manage access to resources within a single
domain. These groups can have as their members:
Groups with global scope
Groups with universal scope
Accounts
Other groups with domain local scope
A mixture of any of the above
For example, to give five users access to a particular printer, you could
add all five user accounts in the printer permissions list. If, however,
you later want to give the five users access to a new printer, you would
again have to specify all five accounts in the permissions list for the
new
printer.
With a little planning, you can simplify this routine administrative task
by creating a group with domain local scope and assigning it permission to
access the printer. Put the five user accounts in a group with global
scope
and add this group to the group having domain local scope. When you want
to
give the five users access to a new printer, assign the group with domain
local scope permission to access the new printer. All members of the group
with global scope automatically receive access to the new printer.
2. When using Universal group,client will contact GC to check permission.
It will lead to the performance issue if you don't have a GC in current
site.
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================
--------------------
microsoft.public.windows.server.migration:25141From: "P" <p@xxxxx>
Subject: Universal Groups
Date: Tue, 26 Sep 2006 16:38:52 +0800
Lines: 25
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2900.2869
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2962
X-RFC2646: Format=Flowed; Original
Message-ID: <e1a6scU4GHA.1492@xxxxxxxxxxxxxxxxxxxx>
Newsgroups: microsoft.public.windows.server.migration
NNTP-Posting-Host: 203.19.211.250
Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP05.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
do,X-Tomcat-NG: microsoft.public.windows.server.migration
Hi
Just wondering, in a win2003 native forest, is there any negative
administrative overheads using universal groups exclusively? (ie no more
global/local)
The reason I ask is that I have a major intraforest migration I have to
controllerand ADMT is a little too smart for its own good in the sense that it
converts domain local groups to universal and then back to local when the
members are migrated. But the resource server is also the domain
and thus the DCPromo will happen much later. Therefore I need to keep the
local groups as universal until the complete conversion is finished.
Given that I'm running win2003 native AD, and given that on completion of
this process its all a single forest/domain, do I actually improve
performance by converting back to domain local?
p.s I have something like 30000 (don't ask) local groups to move from one
domain to another.
thanks
Paul
.
- Follow-Ups:
- Re: Universal Groups
- From: Vincent Xu [MSFT]
- Re: Universal Groups
- References:
- Universal Groups
- From: P
- RE: Universal Groups
- From: Vincent Xu [MSFT]
- Universal Groups
- Prev by Date: Re: Security Translation on ADMT2.0 problem
- Next by Date: RE: WinR2, FSMT and Printer Migration utility 3.1
- Previous by thread: RE: Universal Groups
- Next by thread: Re: Universal Groups
- Index(es):
Relevant Pages
|