CERTIFICARSE hace la diferencia …
Groups
Chapter 4
1
Creating and Managing Groups
Lesson 1
2 CERTIFICARSE hace la diferencia …
Group Accounts
Group – AD objects that contain users, computers and other
entities. (have SIDS)
Groups are used for easier management of
users/computers/resources
Access token identifies groups to which a users belongs/rights
assigned
2 Types of groups:
[Link] group for e-mail
[Link] groups to assign limited permission to groups that
need access to resources or to deny access
3 CERTIFICARSE hace la diferencia …
Example of Access Token
4 CERTIFICARSE hace la diferencia …
Group Accounts
Rights and privileges are assigned at the group level
Groups can be nested (membership by inheritance)
User’s rights and privileges through group
memberships are cumulative
5 CERTIFICARSE hace la diferencia …
Group/User relationship
Group 1
Group 3 is a
member
Group 2 of Group 1
Group 3
6 CERTIFICARSE hace la diferencia …
Group Scope
A group’s scope determines the extent to which the
group can be nested in other groups or referenced in
ACLs on the resources in the AD domain or forest. |
3 Group scopes:
Domain local groups
Global domain groups
Universal groups
7 CERTIFICARSE hace la diferencia …
Domain Local Groups
To assign access permissions for local domain
resources only (domain scope)
Can have members from anywhere in the forest or
from trusted domains in other forests –users
accounts, other domain local, global and universal
groups.
Used as resources group
8 CERTIFICARSE hace la diferencia …
Domain Local Group Example
Domain C
Domain B
Domain A
User 2
Printer Group Engineering
User 1 (Domain Local) (Global Group)
User 1
Engineering
User 2
Printer ACL
Printer Group - Print
9 CERTIFICARSE hace la diferencia …
Global Domain Groups
To provide access to resources in other trusted
domains, to group users
Can have members from within their own domain
only – only user accounts and other global groups
Can be granted access to resources or placed into
local/domain local groups in any trusting domain
10 CERTIFICARSE hace la diferencia …
Global Domain Group Example
Domain A Domain B
Group 2
User1
Accountants
Group 1
Accountants
(Global Group) Domain C
User 1
Group 1
Printer ACL
Accountants
11 CERTIFICARSE hace la diferencia …
Universal Groups
Grant access to resources in all trusted
domains in the forest
Can have members from any domain in a
forest or trusting domain in other forests
Can be granted access to resources in any
domain
Only available in Windows 2003 or 2008
domain functional level
12 CERTIFICARSE hace la diferencia …
Group Strategy
Put users into global domain group. A global group can be
thought of as an Accounts group.
Put resources into domain local (or machine local) groups.
A local group can be thought of as a Resource group.
Put a global group into any domain local (or machine
local) group in the forest
Assign permissions for accessing resources to the domain
local (or machine local) groups that contain them
Use Universal groups to grant access to resources in
multi-domain environments where access is needed
across domain trees.
13 CERTIFICARSE hace la diferencia …
Group Strategy Example
Domain A Domain B
Engineers Engineers
(Global Group) (Global Group)
Database Access
(Domain Local G.) Domain C
Domain A Engineers
Domain B Engineers
Domain C Engineers
Engineers
ACL
(Global Group)
Database Database Access
Allow Write/Read
14 CERTIFICARSE hace la diferencia …
Default User Account Membership
Built-in groups are automatically created in Windows
Server 2003 to reflect most common attributes and
tasks
Domain Users/Users
Domain Admins/Administrators
15 CERTIFICARSE hace la diferencia …
Special Groups
EVERYONE
Network
Interactive
Service
System
Authenticated Users
SELF
CREATOR OWNER
16 CERTIFICARSE hace la diferencia …
User Profiles
Profiles customize user environment, store profiles on server
(roaming), restrict changes through mandatory profiles
Local profiles are stored on a computer when each user logs
in.
17 CERTIFICARSE hace la diferencia …
¡Gracias por su atención!
¿Alguna pregunta?
18 CERTIFICARSE hace la diferencia …