Solved

Universal Groups Exchange 2010

Posted on 2014-02-06
2
318 Views
Last Modified: 2014-02-06
Hi experts,

I asked a similar question before, but I`d like to be sure before I do a fault.

In the past we created global security groups in our active directory which are used for NTFS-privileges on our network.

In Exchange2010 those groups are now shown as "Non-Universal E-Mail groups".

I need to convert some of them because of auto-responding functionality. Will the conversion break any NTFS-function?

Otherwise I would convert those groups.
We have a single domain and forest...


Best regards
Roland
0
Comment
Question by:Systemadministration
2 Comments
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 39839069
You will not lose any NTFS functionality. I have talked about Mail Enabled Security Groups in the past and personally i do not like them. Although you can use them and they work perfectly fine, sometimes people get confused when you have a mix of Distribution and Mail Enabled Security Groups.

Example.
If you have a department "Accounting" with a mail enabled security group, and for whatever reason (projects normally) you would add someone from another department to this group so that they can get project updates, so you add someone from Marketing Department.

You have now done 2 things.
1. You have provided access to that user in the Martketing Department so they they can receive projects updates because they are part of the Accounting Mail Enabled Security Group.

2. You have also provided this user from the marketing department access to Shares or Directories that only Accounting should have access to. This now becomes a security concern because the user from Marketing may not know they have access to files or directories but if they stumble accross an Accounting direcotry they may see information which is probably confidential. I have seen this a lot and Security Audits will always fail if there was not a Change process in place and reasoning for this user to have access to these directories.

That being said everything will work fine. I just wanted to provide my opinion and experience when dealing with a mixture of distribution and mail enabled security groups.

Will.
0
 

Author Closing Comment

by:Systemadministration
ID: 39839098
Thanks!
Great Answer
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
how to add IIS SMTP to handle application/Scanner relays into office 365.

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question