Active Directory Groups, set up with Double Groups.

I have recently taken over as admin for a company.  One of my first tasks has been to clean up the active directory, I have user accounts that haven't been disabled, groups and users in lots of OU's for no reason.  Frankly it is just messy.  One of the things that has me stumbed is the double groups. For example I have  "Real Estate Global" group with users and a "Real Estate" group with the only member is the "real estate Global" group; and there is a " Reception Global" group with users and a "Reception" group with only the "Reception Global" as a member.  There are a few of these:
From what I can see there are no GPO or security settings for this, why would it be set this way?
CobraCatsAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

PlaceboC6Commented:
Maybe they are following that old MS best practices of creating a domain local group and then cramming global groups inside of the domain local group.

They used to practice that back in the day.
0
LauraEHunterMVPCommented:
> "They used to practice that back in the day."

And still do, in environments that contain multiple domains within a single forest or across trust relationships.  It's a matter of group scope, where certain types of groups can only contain users from or grant permissions to resources within the same domain.

If you're in a single-domain environment (you haven't specified), make everything a global group and be done with it.  If someone did AGUDLP group nesting in a single-domain environment, they were following MCSE exam-guide memorization bullet points without understanding how they do (and do not) apply in real-world scenarios.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
PlaceboC6Commented:
Yes.  I suppose I was mainly feeling what you mentioned in your second paragraph.  Someone was studying for an exam and set it up (assuming single domain).
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.