Solved

Universal Groups Exchange 2010

Posted on 2014-02-06
2
317 Views
Last Modified: 2014-02-06
Hi experts,

I asked a similar question before, but I`d like to be sure before I do a fault.

In the past we created global security groups in our active directory which are used for NTFS-privileges on our network.

In Exchange2010 those groups are now shown as "Non-Universal E-Mail groups".

I need to convert some of them because of auto-responding functionality. Will the conversion break any NTFS-function?

Otherwise I would convert those groups.
We have a single domain and forest...


Best regards
Roland
0
Comment
Question by:Systemadministration
2 Comments
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 39839069
You will not lose any NTFS functionality. I have talked about Mail Enabled Security Groups in the past and personally i do not like them. Although you can use them and they work perfectly fine, sometimes people get confused when you have a mix of Distribution and Mail Enabled Security Groups.

Example.
If you have a department "Accounting" with a mail enabled security group, and for whatever reason (projects normally) you would add someone from another department to this group so that they can get project updates, so you add someone from Marketing Department.

You have now done 2 things.
1. You have provided access to that user in the Martketing Department so they they can receive projects updates because they are part of the Accounting Mail Enabled Security Group.

2. You have also provided this user from the marketing department access to Shares or Directories that only Accounting should have access to. This now becomes a security concern because the user from Marketing may not know they have access to files or directories but if they stumble accross an Accounting direcotry they may see information which is probably confidential. I have seen this a lot and Security Audits will always fail if there was not a Change process in place and reasoning for this user to have access to these directories.

That being said everything will work fine. I just wanted to provide my opinion and experience when dealing with a mixture of distribution and mail enabled security groups.

Will.
0
 

Author Closing Comment

by:Systemadministration
ID: 39839098
Thanks!
Great Answer
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question