?
Solved

Any suggestions for Security Group OU structure in AD (Role based access)

Posted on 2016-07-29
6
Medium Priority
?
145 Views
Last Modified: 2016-08-04
I'm trying to think of an easy way without being over-complicated, to organize OU in AD to manage security groups.
Here's what I'm looking at now:
partial OU screenshot
Does anyone else organize similar to that?

The idea of Groups > Access > File > Servers, would be that I create a security group called something like "ACL_Server1_inetpub_write", and then add that group to have write access to C:\inetpub on "Server1".
Versus giving a user local Admin rights entirely to Server1.

Then I could have a Role Group called "Server1 Web Editors", which would be a member of ACL_Server1_inetpub_write.
Am I over-complicating Role Based Access, given this idea, OU structure and naming convention?
0
Comment
Question by:garryshape
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 74

Accepted Solution

by:
Jeffrey Kane - TechSoEasy earned 2000 total points
ID: 41735345
You really don't want to be organizing your AD OU's by security group.  That would be difficult to manage in the long term.

In order to give you advice though, it would be helpful to know more about your environment.  How many users, what industry, how many physical locations?
0
 
LVL 74

Assisted Solution

by:Jeffrey Kane - TechSoEasy
Jeffrey Kane - TechSoEasy earned 2000 total points
ID: 41735348
By the way -- you never have to give a user local administrator rights on a server for them to manage IIS.

Instead, they just need to install the IIS Management Console on their own computer.

http://www.iis.net/downloads/microsoft/iis-manager

And if it's IIS 8, see this how-to:  http://www.sherweb.com/blog/configure-iis-8-remote-administration/
0
 

Author Comment

by:garryshape
ID: 41735349
I got the idea from this video, at this timestamp you can see a similar OU structure; https://youtu.be/vvhwN5bOyV8?t=1370   

The environment is school. Couple hundred staff, couple thousand student, ultimately. no security groups for the student body yet. I'm not sure if I need one for them. Im' thinking maybe just a "Student" security group, and Deny it logon access to staff computers.
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 

Author Comment

by:garryshape
ID: 41735352
Hey that's interesting. So it allows like editing the webpages?
The user was going to get RDP into the server, but this solution is a workaround to that?
0
 

Author Comment

by:garryshape
ID: 41735391
Also I'm not organizing OU by security group, I'm organizing Security Group by OU.  
I will have other OU's for users and computers
0
 
LVL 74

Assisted Solution

by:Jeffrey Kane - TechSoEasy
Jeffrey Kane - TechSoEasy earned 2000 total points
ID: 41743474
Hey that's interesting. So it allows like editing the webpages?
The user was going to get RDP into the server, but this solution is a workaround to that?

Yes.  There is no reason for someone who just needs to administer IIS and web sites to have full access to the entire server.  They can install the IIS Admin Tools on their own computer, connect to the web server and do whatever they need to do within the confines of IIS.

So, I fully understand where you got the idea -- but I think -- as you had also thought -- Role Based Access may actually over-complicate things for you.  I don't think that your scenario will benefit that much from RBAC.  Especially now that you know about things like IIS Remote Management.  

Basic security groups coupled with a well managed Group Policy should provide you with everything you need to keep things under control.  

One thing to remember is that the more complex something is to manage, the less likely it will be managed at all.
1

Featured Post

Supports up to 4K resolution!

The VS192 2-Port 4K DisplayPort Splitter is perfect for anyone who needs to send one source of DisplayPort high definition video to two or four DisplayPort displays. The VS192 can split and also expand DisplayPort audio/video signal on two or four DisplayPort monitors.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Getting to know the threat landscape in which DDoS has evolved, and making the right choice to get ourselves geared up to defend against  DDoS attacks effectively. Get the necessary preparation works done and focus on Doing the First Things Right.
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question