I am about to create new AD domain and install various application server like Advanced CRM, Share point,Biz talk server, SQL server
In rule server.

Previously I had worked with one or two application server in one AD domain.

I want to create universal security group on each server and assign necessary rights to enterprise admins, domain admins, power users, authenticated users.

I was thinking of creating this built in group enterprise admins, domain admins, power users, authenticated users. in ADUC on DC.

but should I create universal security on each server and under universal security group  for example--should I create server management group and then assign security permissions.
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Am I to assume the new domain is a child domain or another tree within the same forest?  Or is this to be a new domain in a new forest?
Manikandan NarayanswamySecurity Specialist & IBM Security GuardiumCommented:

The easiest way could be create a Universal security group in active directory along with server management group . Add all the servers in the server management group. Then add this group to the universal security group which you created. Then define the members who would have rights to access these servers.


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.