We help IT Professionals succeed at work.

ACTIVE DIRECTORY SERVER

There is a new AD server created having new servers like CRM, BIZTALK , INRULE servers being added

I am attaching sheet ,

the sheet gives some information as to how groups are to be created. They need my advise

as per sheet, as to how groups are created  I have come to some conclusion believe one will be creating will be universal security Group –Universal or Global? I believe Forest functional level to be windows server 2003 and above.

I believe there will be one AD with one global catalog.

I believe below will be added on the AD server.

Domain Users-Universal security group –Global- domain users where u will be adding below users.
Domain Computers-Universal Security group-Global- where u will be adding domain computers.

DOS-DMV-BIZ-ApplicationUsers-UAT
DOS-DMV-BIZ-IsolatedHostUser-UAT
DOS-DMV-BIZ-Administrators-UAT
DOS-DMV-BIZ-ServerOperators-UAT
DOS-DMV-BIZ-SSOAdministrators-UAT
DOS-DMV-BIZ-SSOAffiliateAdministrators-UAT
DOS-DMV-BIZ-BAMPortalUsers-UAT

am I correct, also SAFETY\svcDMVCRMinstUAT
SAFETY\svcDMVCRMsvcsUAT
SAFETY\svcDMVCRMdbUAT
SAFETY\svcDMVCRMsndbxUAT
SAFETY\svcDMVCRMmdlwrUAT

SAFETY\SVCDMVBIZINSUAT
SAFETY\SVCDMVBIZINHUAT
SAFETY\SVCDMVBIZISHUAT

where above accounts are created on AD server or individual CRM and biz talk server

just needed expert advise.
Copy-of-Groups--Permissions.xlsx
Comment
Watch Question

Senior Solution Architect
Most Valuable Expert 2015
Top Expert 2015
Commented:
Accounts are created on the Active Directory Server.

Will.

Author

Commented:
I believe these will be domain users:DOS-DMV-BIZ-ApplicationUsers-UAT
 DOS-DMV-BIZ-IsolatedHostUser-UAT
 DOS-DMV-BIZ-Administrators-

what kind of accounts will be this, can u go through excel sheet
UATSAFETY\svcDMVCRMsvcsUAT
 SAFETY\svcDMVCRMdbUAT
 SAFETY\svcDMVCRMsndbxUAT
 SAFETY\svcDMVCRMmdlwrUAT
Will SzymkowskiSenior Solution Architect
Most Valuable Expert 2015
Top Expert 2015

Commented:
Global Groups = Only Individual Users can be added to this type of Group

Universal Groups = Groups and Users can be added to this Group Type

Will.

Author

Commented:
why not domain local group for managing each server individually?
Will SzymkowskiSenior Solution Architect
Most Valuable Expert 2015
Top Expert 2015

Commented:
Are you dealing with multiple different domains? If not when do not use Domain Local Groups.

Group Types Explained
https://technet.microsoft.com/en-ca/library/cc755692%28v=ws.10%29.aspx

Will.