Nesting Active Directory Groups

|
Rather Have Fast and Secure Remote
Control?
|
Some of you will remember the group usage strategy outlined by Microsoft for NT 4 domain environments. It suggested that you place user accounts into global groups according to needs, assign permissions to local groups, and then place global groups into local groups, thereby giving users access to resources. This model was often referred to as AGLP:
Accounts (get placed into) Global Groups (which are then placed in) Local Groups (who are ultimately assigned) Permissions
Although there are many different possibilities in terms of assigning permissions, the above method is amongst the most scalable. By the same token, a methodology exists in Windows 2000 that you should follow.
Accounts > Global Groups > Domain Local Groups > Permissions
Note that the model can extend beyond this, however. For example, you can nest global groups (which is useful if you have a few global groups in the same domain who you wish to further organize), or place global groups from different domains into a Universal group. With a Universal group, this would then make the model:
Accounts > Global Groups > Universal > Domain Local Groups > Permissions
The idea is simple – group users with common needs using global groups (or universal if you wish), and then place that group into a domain local group, which is assigned permissions to a resource. This allows many users to have access to the resource, while assigning permissions only once. A name for the new model that you won’t forget? Try AGULP (just remember that the L is for domain local now)
Written by Dan DiNicolo - Visit WebsiteNext post in Windows 2000:
Publishing Resources in Active Directory
Next post in Active Directory:
Publishing Resources in Active Directory
Next post in User Account:
Active Directory Object Security
Previous post in Windows 2000:
Active Directory Group Concepts
Previous post in Active Directory:
Active Directory Group Concepts
Previous post in User Account:
Active Directory Group Concepts
All Tutorials by Category:
- CCDA Study Guide
- CCNA Study Guide Chapter 01
- CCNA Study Guide Chapter 02
- CCNA Study Guide Chapter 03
- CCNA Study Guide Chapter 04
- CCNA Study Guide Chapter 05
- CCNA Study Guide Chapter 06
- CCNA Study Guide Chapter 07
- CCNA Study Guide Chapter 08
- CCNA Study Guide Chapter 09
- CCNA Study Guide Chapter 10
- CCNA Study Guide Chapter 11
- CCNA Study Guide Chapter 12
- Cognos
- Computer Hardware
A
C
D
E
F
G
H
I
L
M
N
Entire site Copyright © 1999-2007 2000Trainers.com, all rights reserved.
Content on this site may not be copied or reproduced in any way without permission.


