Re: Domain Local Groups and Member Servers

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 01/21/04


Date: Wed, 21 Jan 2004 02:27:25 -0500

We do this in our company, we have tens of thousands of domain local groups
assigned to resources on a couple thousand servers and it works fine. About
the only thing I could probably say would be a problem is if you are
assigning rights. The GUI won't display a domain local group but the command
line tools (like ntrights) have no problem assigning them.

-- 
www.joeware.net
"Mark Ayers" <n2sami @ attbi . com> wrote in message
news:e3qBkQ53DHA.3656@TK2MSFTNGP11.phx.gbl...
> Some folks I know are advocating doing away with the use of local groups
on
> member servers.  They would assign rights on member severs directly to
> domain local groups rather than to local groups on the member server.
>
> Can I get a sanity check?
>
> Am all wet for thinking this is a heinous crime? What are the benefits if
I
> am wrong? What are the technical problems that will result if I am right
but
> they proceed down their path?
>
> I am used to u->g->l<-r except on a dc where it is u->g->dl<-r they would
> use u->g->dl<-r everywhere.
>
> Any sources cited will be appreciated. Heck, just bothering to think about
> my problem is appreciated.
>
>


Relevant Pages

  • Re: SMS 2003 - adding Secondary site... driving me -mental- :-/
    ... Domain controllers DO have local groups, they just work a little differently ... on DCs than they do on member servers and workstations. ... There is a section of procedures for SMS Account Management near the end. ...
    (microsoft.public.sms.setup)
  • Re: NT4 BDC to Win2k3 server
    ... Well, if i now understand correctly, you are saying you want to upgrade your ... As long as you still have a PDC, the domain local groups will ... > Win2k3 server be a member server in the NT4 domain. ...
    (microsoft.public.windows.server.migration)
  • Re: 2005 Cluster Install Error
    ... solution of creating machine local groups to which I add Domain Global ... given they do document the machine local groups as SQL Server security ... > I can see the need to promote Machine Local Groups to Domain Local Groups ... > when we are talking about clusters because the level of scope. ...
    (microsoft.public.sqlserver.clustering)
  • Re: 2005 Cluster Install Error
    ... > solution of creating machine local groups to which I add Domain Global ... > given they do document the machine local groups as SQL Server security ... >> I can see the need to promote Machine Local Groups to Domain Local Groups ... >> when we are talking about clusters because the level of scope. ...
    (microsoft.public.sqlserver.clustering)
  • Re: Shared Folder NTFS Permission Problems with Domain Accounts
    ... I look after a firm which has two DCs and four more servers and I've ... I can share the folder without a problem and then when selecting NTFS ... You cannot use LOCAL groups of the domain on non-DCs unless you are ... I've created I just can't select any of the built-in security principals ...
    (microsoft.public.windows.server.general)