0% found this document useful (0 votes)
3 views18 pages

Understanding Active Directory Groups

The document discusses the creation and management of groups in Active Directory, highlighting the types of groups (Distribution and Security), their purposes, and how access tokens work. It explains group scopes, including Domain Local, Global Domain, and Universal groups, and provides strategies for organizing users and resources. Additionally, it covers default user account memberships and special groups in Windows Server 2003.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views18 pages

Understanding Active Directory Groups

The document discusses the creation and management of groups in Active Directory, highlighting the types of groups (Distribution and Security), their purposes, and how access tokens work. It explains group scopes, including Domain Local, Global Domain, and Universal groups, and provides strategies for organizing users and resources. Additionally, it covers default user account memberships and special groups in Windows Server 2003.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CERTIFICARSE hace la diferencia …

Groups

Chapter 4

1
Creating and Managing Groups

Lesson 1

2 CERTIFICARSE hace la diferencia …


Group Accounts

 Group – AD objects that contain users, computers and other


entities. (have SIDS)
 Groups are used for easier management of
users/computers/resources
 Access token identifies groups to which a users belongs/rights
assigned
 2 Types of groups:
[Link] group for e-mail
[Link] groups to assign limited permission to groups that
need access to resources or to deny access

3 CERTIFICARSE hace la diferencia …


Example of Access Token

4 CERTIFICARSE hace la diferencia …


Group Accounts

 Rights and privileges are assigned at the group level

 Groups can be nested (membership by inheritance)

 User’s rights and privileges through group


memberships are cumulative

5 CERTIFICARSE hace la diferencia …


Group/User relationship

Group 1

Group 3 is a
member
Group 2 of Group 1

Group 3

6 CERTIFICARSE hace la diferencia …


Group Scope

 A group’s scope determines the extent to which the


group can be nested in other groups or referenced in
ACLs on the resources in the AD domain or forest. |
3 Group scopes:
Domain local groups
Global domain groups
Universal groups

7 CERTIFICARSE hace la diferencia …


Domain Local Groups

 To assign access permissions for local domain


resources only (domain scope)

 Can have members from anywhere in the forest or


from trusted domains in other forests –users
accounts, other domain local, global and universal
groups.

 Used as resources group

8 CERTIFICARSE hace la diferencia …


Domain Local Group Example

Domain C
Domain B
Domain A

User 2
Printer Group Engineering
User 1 (Domain Local) (Global Group)
User 1
Engineering
User 2

Printer ACL

Printer Group - Print

9 CERTIFICARSE hace la diferencia …


Global Domain Groups

 To provide access to resources in other trusted


domains, to group users

 Can have members from within their own domain


only – only user accounts and other global groups

 Can be granted access to resources or placed into


local/domain local groups in any trusting domain

10 CERTIFICARSE hace la diferencia …


Global Domain Group Example

Domain A Domain B

Group 2
User1
Accountants
Group 1
Accountants
(Global Group) Domain C

User 1
Group 1

Printer ACL
Accountants

11 CERTIFICARSE hace la diferencia …


Universal Groups

 Grant access to resources in all trusted


domains in the forest

 Can have members from any domain in a


forest or trusting domain in other forests

 Can be granted access to resources in any


domain
 Only available in Windows 2003 or 2008
domain functional level

12 CERTIFICARSE hace la diferencia …


Group Strategy
 Put users into global domain group. A global group can be
thought of as an Accounts group.
 Put resources into domain local (or machine local) groups.
A local group can be thought of as a Resource group.
 Put a global group into any domain local (or machine
local) group in the forest
 Assign permissions for accessing resources to the domain
local (or machine local) groups that contain them
 Use Universal groups to grant access to resources in
multi-domain environments where access is needed
across domain trees.

13 CERTIFICARSE hace la diferencia …


Group Strategy Example

Domain A Domain B

Engineers Engineers
(Global Group) (Global Group)

Database Access
(Domain Local G.) Domain C

Domain A Engineers
Domain B Engineers
Domain C Engineers
Engineers
ACL
(Global Group)
Database Database Access
Allow Write/Read

14 CERTIFICARSE hace la diferencia …


Default User Account Membership

 Built-in groups are automatically created in Windows


Server 2003 to reflect most common attributes and
tasks
 Domain Users/Users
 Domain Admins/Administrators

15 CERTIFICARSE hace la diferencia …


Special Groups

 EVERYONE
 Network
 Interactive
 Service
 System
 Authenticated Users
 SELF
 CREATOR OWNER

16 CERTIFICARSE hace la diferencia …


User Profiles

 Profiles customize user environment, store profiles on server


(roaming), restrict changes through mandatory profiles

 Local profiles are stored on a computer when each user logs


in.

17 CERTIFICARSE hace la diferencia …


¡Gracias por su atención!
¿Alguna pregunta?

18 CERTIFICARSE hace la diferencia …

You might also like