Solved

Will using the distribution group as security group impact the Active Directory performance?

Posted on 2009-07-05
4
224 Views
Last Modified: 2012-05-07
Hello,
Good Day,

My question is very simple and straighforward.

If i use the distribution group as security group, will it impact the AD performance? ... In other words, using the distribution group is for email purpose only but if i use it as security group as well for resource access, will it make my users logon time slow or something? ... or will it create an AD replication bottleneck?

Appreciate your quick response.

Thanks in advance
0
Comment
Question by:amyassein
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 74

Expert Comment

by:Glen Knight
ID: 24780522
Security groups Groups that can have security descriptors associated with them. You define security groups in domains using Active Directory Users And Computers.

Distribution groups Groups that are used as e-mail distribution lists. They can't have security descriptors associated with them. You define distribution groups in domains using Active Directory Users And Computers.

Extract from: http://technet.microsoft.com/en-us/library/bb726978.aspx
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 125 total points
ID: 24780526
It could depending on how many groups the user is a member of.  
You can run into an issue known as "token bloat"
http://support.microsoft.com/kb/327825
New resolution for problems with Kerberos authentication when users belong to many groups
http://technet.microsoft.com/en-us/library/cc757478(WS.10).aspx
 ...but as you can see there are also fixes/workarounds in place
There are other concerns with security vs distro lists.  See the thread below, really great discussion from Brian, Simon, and Chris a few months ago
http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_24349300.html
Thanks
Mike
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 24780543
but of course you can create mail enabled security groups so why bother with DL's when one group will do both?
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24780552
demazter that was the entire debate here:
http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_24349300.html
I can see both sides of the argument.
Thanks
Mike
0

Featured Post

Major Incident Management Communications

Major incidents and IT service outages cost companies millions. Often the solution to minimizing damage is automated communication. Find out more in our Major Incident Management Communications infographic.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question