Re: Group limitations
From: Jonathan (jonsteph@nospam.carolina.rr.com)
Date: 04/08/03
- Previous message: derek / nul: "Re: Group limitations"
- In reply to: derek / nul: "Re: Group limitations"
- Next in thread: Lane Romel: "Re: Group limitations"
- Reply: Lane Romel: "Re: Group limitations"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Jonathan <jonsteph@nospam.carolina.rr.com> Date: Tue, 08 Apr 2003 01:38:49 GMT
The limitation is actually closer to 5,000, and only applies to
Windows 2000. Group membership is stored as a multi-valued attribute
on the group object. Attribute size is limited to a finite size due to
the requirements of AD replication. This limitations affect on group
membership is to limit it to about 5,000 users.
Domain Users is a special group, in that users aren't actually a
member of that group by default. By default, all users are members of
the Domain Users group, and that group is set as their Primary Group.
Windows 2000 considers a user to be a member of their primary group
even if they are not listed in the group's Member attribute. In fact,
if you use LDP.EXE or ADSIEDIT.MSC and look at the member attribute of
the Domain Users group, you'll see that it is empty (in LDP, empty
attributes aren't listed).
If you change a user's primary group, they will be explicity added to
the Member attribute of the Domain Users group.
This limitation doesn't just affect group membership. It also affects
any other multivalued attribute -- such as activated DHCP servers.
Windows 2003 adds a feature call linked-value replication, so this
limitation does not apply.
There's a KB article that describes this, but I can't find it on
support.microsoft.com right now.
- Jonathan
On Mon, 07 Apr 2003 21:13:34 GMT, derek / nul <abuse@sgrail.org>
wrote:
>I have seen 28,000 in a 'users' group on a w2k domain?
>
>On Mon, 7 Apr 2003 12:38:53 -0400, "Lane Romel" <!laneromel@sympatico.ca> wrote:
>
>>While doing a profile for a domain structure I came across a Microsoft
>>document that claims you can only have 4000 users in a group. Is this true
>>or is the doccument out of touch?
>>
- Previous message: derek / nul: "Re: Group limitations"
- In reply to: derek / nul: "Re: Group limitations"
- Next in thread: Lane Romel: "Re: Group limitations"
- Reply: Lane Romel: "Re: Group limitations"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|