There are best practices setup using these groups as well as some groups can
contain others. For the most part just ignore Universal groups if you are
in a single domain, its value has two functions one for multiple domains the
other for authentication with Global Catalogs .
Use Global Catalogs to group your users and use Domain Local to provide
access to resources. For example:
You have a share named contracts that you want to provide access to Halle
Berry and Yogi Bear. You create a global group named G_Hollywood and you
make Halle and Yogi members of this global group. Then create a Domain
Local group named DL_contract. Browse to the share and go to the security
tab and provide the Share and NTFS permissions to the DL_contract group.
Finally make the G_Hollywood group a member of the DL_contract group. Once
Yogi and Halle log off and log back on they will have access to the
resource.
Group users in Global groups and provide access via Domain Local Groups.
Paul Bergson MCT, MCSE, CNE, CNA, CCA
Jesse_James said:
When I create a new object group in my Active Directoryunder Group Scope,
what is the difference between: