Domain Local Groups and Member Servers

From: Mark Ayers (_at_)
Date: 01/20/04


Date: Tue, 20 Jan 2004 12:28:59 -0800

Some folks I know are advocating doing away with the use of local groups on
member servers. They would assign rights on member severs directly to
domain local groups rather than to local groups on the member server.

Can I get a sanity check?

Am all wet for thinking this is a heinous crime? What are the benefits if I
am wrong? What are the technical problems that will result if I am right but
they proceed down their path?

I am used to u->g->l<-r except on a dc where it is u->g->dl<-r they would
use u->g->dl<-r everywhere.

Any sources cited will be appreciated. Heck, just bothering to think about
my problem is appreciated.



Relevant Pages

  • Re: A-G-DL-P strategy
    ... I believe you are referring to Domain Local groups, ... You can use Domain Local groups as per the recommendation - and the ... cannot see these groups on your member servers if because you are still ...
    (microsoft.public.windows.server.active_directory)
  • Re: howto: migrate fileserver resources from NT4 BDC to W2003 member server
    ... Microsoft recommends even for single domain ... permissions to files and directories to this local groups. ... These local groups exists an NT4 PDC's, BDC's and NT4 Member Servers as ...
    (microsoft.public.windows.server.migration)
  • Re: A-G-DL-P strategy
    ... If not start using LG (local groups) created on your member server... ... >I believe you are referring to Domain Local groups, ... > cannot see these groups on your member servers if because you are still ...
    (microsoft.public.windows.server.active_directory)
  • Re: UGLP rule
    ... groups in AD as wel as on member servers. ... > Using local groups is a real burden as they're not centrally managed - ... > real valid reason to do so. ...
    (microsoft.public.windows.server.active_directory)
  • Re: howto: migrate fileserver resources from NT4 BDC to W2003 member server
    ... in NT4 is no such thing as domain ... global groups and domain local groups. ... visible on member servers until the domain is switched from mixed mode into ...
    (microsoft.public.windows.server.migration)