Using global groups to assign access to resources

From: Rob (robin.jackson@za.pwcglobal.com)
Date: 02/04/03


From: "Rob" <robin.jackson@za.pwcglobal.com>
Date: Mon, 3 Feb 2003 22:45:09 -0800


In a Windows 2000 AD single domain environment running in
native mode - why use domain local groups to control
access to resources? What are the drawbacks of simply
adding users to global groups and then assigning access to
the resource with the global group?



Relevant Pages

  • Re: Using global groups to assign access to resources
    ... Alternatively what are the drawbacks of simply adding users to domain local ... groups in that environment? ... > access to resources? ... > adding users to global groups and then assigning access to ...
    (microsoft.public.win2000.security)
  • Global & Domain Local Groups
    ... Aside from determining what objects can be members, ... In a single domain environment, ... problems with using global groups to assign access to resources at the ... (Aside from violating the almighty AGDLP doctrine) ...
    (microsoft.public.win2000.active_directory)
  • Re: Security Group Confusion
    ... forest', at least that's how I read it. ... > You want to make users members of global groups and add the global groups to ... > Domain local are only used for resources in their own domain but can contain ...
    (microsoft.public.windows.server.active_directory)
  • Re: Security Group Confusion
    ... You want to make users members of global groups and add the global groups to ... Domain local are only used for resources in their own domain but can contain ... Prev by Date: ...
    (microsoft.public.windows.server.active_directory)