Solved

Assigning AD permissions by OU

Posted on 2011-03-14
8
872 Views
Last Modified: 2012-05-11
We recently added a 2nd DC; which operates on Server 2008 R2. The original DC is 2003 SP2. This weekend, i modified our user placements & organizational unit (OU) folders. The structure is now more in-line with our company and policies can be assigned accordingly, althouth we have not reapplied ANY permissions.

My challenge, is when we are assigning permissions to an object like sharepoint, i used to be able to assign to an OU...domain\OU_group. All of the current permissions need to be changed to reflect the change we made to the OU structure. It seems that we can not search based on our new OU names.
0
Comment
Question by:mray77
  • 4
  • 4
8 Comments
 
LVL 11

Expert Comment

by:RickSheikh
ID: 35129250
If the permissions were based on AD Groups then the groups' changed location in AD should not call for this issue you are sighting. I am not sure what you mean when you say that the permissions had OU references ?
0
 

Author Comment

by:mray77
ID: 35129312
What i mean is instead of assigning permissions to mydomain\joe_smith they are assigned to mydomain\executive or mydomain\sales so we are assigning to the OU group not the individual users, at least for sharepoint. in sharepoint, there is a domain query that allows you to enter either the user or group and it will query AD.
0
 
LVL 11

Accepted Solution

by:
RickSheikh earned 500 total points
ID: 35129402
Are "executives" and "sales" from your last comment AD Groups ? OU and Group objects are distinct things but your reference to an "OU group" is throwing me off. If in fact the executive and sales are AD Groups then the OU hierarchy changes you have made should not be an issue for a sharepoint or any other resource unless the group name was based on DN i.e cn=mygroup,ou=company,dc=domain,dc=local
0
 

Author Comment

by:mray77
ID: 35129439
Should they be? Currently, i have them built as an OU so i can assign different AD permissions. Can i assign separate permission to an AD Group?
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 11

Expert Comment

by:RickSheikh
ID: 35129497
Yes, it is a best practice to assign permissions on AD Group than to an OU where users reside.
0
 

Author Comment

by:mray77
ID: 35129545
So i can have multiple with permissions, but it's best not to have a sub-OU, i should use AD Groups; which i can still assign permissions too? That makes sense.
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 35129611
yes, use AD Groups.
0
 

Author Comment

by:mray77
ID: 35129620
Gotcha. Thanks for explaining this. This makes sense now.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
RSOP Red "X" 7 32
equivalent of Enterprise 2008R2 OS edition in 2016 2 29
vmdk greater than 2TB 2 32
SBS 2003 RWW Login 3 22
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now