Solved

difference between everyone, users and domain users in server 2008?

Posted on 2012-03-28
6
971 Views
Last Modified: 2012-04-16
what's the difference between everyone, users and domain users in server 2008 domain environment? and why by default, the users is in the security group not domain users?
0
Comment
Question by:okamon
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 14

Expert Comment

by:athomsfere
ID: 37779908
Everyone is literally everyone that can hit that system.

Users are local users, and domain users are basically users, but instead of being assigned locally they are assigned by the DC / Active Directory.
0
 

Author Comment

by:okamon
ID: 37780149
Users are local users? so you mean domain users are local users? as by default, in security only has users, there is no domain users. And can you tell me why?
0
 
LVL 11

Accepted Solution

by:
Venugopal N earned 395 total points
ID: 37780448
Every one Group:

The Everyone group includes all members of the Domain Users, Authenticated Users group as well as the built-in Guest account, and several other Built-in security identifiers like SERVICE, LOCAL_SERVICE, NETWORK_SERVICE, etc. . This is a built-in group that cannot be modified.

Users:

Members of this group can perform most common tasks, such as running applications, using local and network printers, and locking the server. By default, the Domain Users group, Authenticated Users, and Interactive are members of this group. Therefore, any user account created in the domain becomes a member of this group.

*Users group contains both the local aswelas domain users by default.

Domain Users:

This group contains all domain users. By default, any user account created in the domain becomes a member of this group automatically. This group can be used to represent all users in the domain. For example, if you want all domain users to have access to a printer, you can assign permissions for the printer to this group (or add the Domain Users group to a local group, on the print server, that has permissions for the printer).


http://technet.microsoft.com/en-us/library/cc756898(v=ws.10).aspx
0
Edgartown IT Case Study

Learn about Edgartown's quest to ensure the safety and security of the entire town's employee and citizen data. Read the case study!

 
LVL 11

Expert Comment

by:Venugopal N
ID: 37780477
After the initial installation of the operating system, only member is the Authenticated Users group(A group that includes all users whose identities were authenticated when they logged on. Membership is controlled by the operating system) of Users group. When a computer joins a domain or promote to DC, the Domain Users group is added to the Users group on the computer.

Hence Users group will have the users which has been created while installing the OS ( Authenticated Users group ) and the Domain Users group.
0
 
LVL 11

Expert Comment

by:Venugopal N
ID: 37780479
0
 

Author Comment

by:okamon
ID: 37784072
why I asked this question is that I have a sbs2011 and the RWA include a portal where users can access the share folders. I wanted to share with external clients as well but only the folder I want to give to them. on the client's user member property, I removed eveything except the "windows sbs RWA users" group, but they still able to access share folders. I checked the share folder permission and see that the everyone if in security, I removed it and changed to "users". But they still had access. I then changed to "Domain users" this time and now they don't have access. So "windows sbs RWA users" group is part of the "Users" group as well?  I checked the "member of" property and it was blank though...
0

Featured Post

The Ultimate Checklist to Optimize Your Website

Websites are getting bigger and complicated by the day. Video, images, custom fonts are all great for showcasing your product/service. But the price to pay in terms of reduced page load times and ultimately, decreased sales, can lead to some difficult decisions about what to cut.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question