Solved

Universal Groups Exchange 2010

Posted on 2014-02-06
2
321 Views
Last Modified: 2014-02-06
Hi experts,

I asked a similar question before, but I`d like to be sure before I do a fault.

In the past we created global security groups in our active directory which are used for NTFS-privileges on our network.

In Exchange2010 those groups are now shown as "Non-Universal E-Mail groups".

I need to convert some of them because of auto-responding functionality. Will the conversion break any NTFS-function?

Otherwise I would convert those groups.
We have a single domain and forest...


Best regards
Roland
0
Comment
Question by:Systemadministration
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 39839069
You will not lose any NTFS functionality. I have talked about Mail Enabled Security Groups in the past and personally i do not like them. Although you can use them and they work perfectly fine, sometimes people get confused when you have a mix of Distribution and Mail Enabled Security Groups.

Example.
If you have a department "Accounting" with a mail enabled security group, and for whatever reason (projects normally) you would add someone from another department to this group so that they can get project updates, so you add someone from Marketing Department.

You have now done 2 things.
1. You have provided access to that user in the Martketing Department so they they can receive projects updates because they are part of the Accounting Mail Enabled Security Group.

2. You have also provided this user from the marketing department access to Shares or Directories that only Accounting should have access to. This now becomes a security concern because the user from Marketing may not know they have access to files or directories but if they stumble accross an Accounting direcotry they may see information which is probably confidential. I have seen this a lot and Security Audits will always fail if there was not a Change process in place and reasoning for this user to have access to these directories.

That being said everything will work fine. I just wanted to provide my opinion and experience when dealing with a mixture of distribution and mail enabled security groups.

Will.
0
 

Author Closing Comment

by:Systemadministration
ID: 39839098
Thanks!
Great Answer
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question