Solved

Will using the distribution group as security group impact the Active Directory performance?

Posted on 2009-07-05
4
223 Views
Last Modified: 2012-05-07
Hello,
Good Day,

My question is very simple and straighforward.

If i use the distribution group as security group, will it impact the AD performance? ... In other words, using the distribution group is for email purpose only but if i use it as security group as well for resource access, will it make my users logon time slow or something? ... or will it create an AD replication bottleneck?

Appreciate your quick response.

Thanks in advance
0
Comment
Question by:amyassein
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 74

Expert Comment

by:Glen Knight
ID: 24780522
Security groups Groups that can have security descriptors associated with them. You define security groups in domains using Active Directory Users And Computers.

Distribution groups Groups that are used as e-mail distribution lists. They can't have security descriptors associated with them. You define distribution groups in domains using Active Directory Users And Computers.

Extract from: http://technet.microsoft.com/en-us/library/bb726978.aspx
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 125 total points
ID: 24780526
It could depending on how many groups the user is a member of.  
You can run into an issue known as "token bloat"
http://support.microsoft.com/kb/327825
New resolution for problems with Kerberos authentication when users belong to many groups
http://technet.microsoft.com/en-us/library/cc757478(WS.10).aspx
 ...but as you can see there are also fixes/workarounds in place
There are other concerns with security vs distro lists.  See the thread below, really great discussion from Brian, Simon, and Chris a few months ago
http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_24349300.html
Thanks
Mike
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 24780543
but of course you can create mail enabled security groups so why bother with DL's when one group will do both?
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24780552
demazter that was the entire debate here:
http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_24349300.html
I can see both sides of the argument.
Thanks
Mike
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question