• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 382
  • Last Modified:

Windows 2003 single domain- Best practice user grouping for folder access

I'm trying to get an easy and clean idea how to group users for folder access permission in Windows 2003 mixed mode single domain.

For example,
       |-Client Billing Info
           |-Client Scores
           |-Client Billing Info

Let's say under Accounting folder, I want to give different access permissions for different sub folders.
I have;


I want to give UserA and UserB modify permission to Client Scores folder and Reports
I want to give UserC read permission to Client Report only
I want to give all read permission to Reservation
I want to deny all to Management.

  • 2
1 Solution
crcsupportAuthor Commented:
I can't add Global group to Global group or Local to Local, but only Global to Local, which makes difficult to group users in inheritance for access permissions.
I don't know it's because the functional level of the domain is windows 2000 mixed mode. I can raise the domain to native mode, but wonder how other big companies do user groupings with large mixed mode....
crcsupportAuthor Commented:

In Windows 2000 mixed mode, Global to Global is not allowed. Domain needs to be raised to Windows 2000 native or Windows 2003 native mode.

Windows 2000 mixed mode: AGDLP (Account to Global to Local to Permission)
Windows 2000/2003 native: AGGUUDLP(Account to Global, Global to Universal, Global/Universal to Local, Local to permission)
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Train for your Pen Testing Engineer Certification

Enroll today in this bundle of courses to gain experience in the logistics of pen testing, Linux fundamentals, vulnerability assessments, detecting live systems, and more! This series, valued at $3,000, is free for Premium members, Team Accounts, and Qualified Experts.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now