Solved

Windows server 2008

Posted on 2016-11-07
5
56 Views
Last Modified: 2016-11-13
Hi,

Please help me to understand in real scenario and how to use it.

1: Differences between Global , Domain local, and universal group and how/where to use it.

Warm Regards
Sanjeev Jha.
0
Comment
Question by:Sanjeev jha
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 30

Expert Comment

by:Rich Weissler
ID: 41877621
Ah, Group Scope and role based access controls.  :-) The differences are important if you have trusts between domains and you're working with forests, etc.

Domain Local Groups can be used to assign rights only to objects in the local domain, but members can be in any domain.
Global Groups can be used to assign rights anywhere, but members have to be in the local domain.
Universal Groups can be used to assign rights anywhere, and can have members from any domain.

NORMALLY, If you are assigning permissions/rights to a share, or a folder, or to an OU in your domain, or to determine who can enroll for a particular type of certificate -- you'd grant that to a Domain Local Group.  In each domain in which there will be consumers who need access to that object -- you'd create a global group and put the relevant users in the global group.  Then you'd simply make the global groups as members of the domain local group.

The abbreviation AGDLP spells things in the opposite direction, but the result is the same... using  "account, global, domain local, permission" and is contrasted by AGUDLP (for "account, global, universal, domain local, permission").  That wikipedia article goes further into explaining role based access controls.
0
 

Author Comment

by:Sanjeev jha
ID: 41877647
Sir: Thanks for your support but I need through Example which can clear my doubt and it will help easily understand.


Warm Regards
Sanjeev Jha.
0
 
LVL 30

Expert Comment

by:Rich Weissler
ID: 41877713
Lets say you have a common administrative share to which your administrative staff needs access.
First, create a Domain Local Group in the same domain as the file server resource... in this case "SHR-AdminCommon".
I would grant that group Read and Change permissions to the share, and Read/Write access to the NTFS folder.
I would then create a Global Group in each domain which will have administrative staff user accounts.  I might call the group "Admin Staff".
Into each of those Global Groups, I'd place my admin staff user accounts.
Into the Domain Local Group (SHR-AdminCommon), I'd make each of the separate Admin Staff Global Groups a member.
0
 
LVL 30

Accepted Solution

by:
Rich Weissler earned 500 total points
ID: 41877760
So, when should you use each type of group?

When assigning rights or permissions -- assign the rights or permissions to a Domain Local Group.  Delegating the ability to perform password changes to users in specific OUs, for example... or permissions to Shares or Folders...

When grouping users, you'll (usually) use Global Groups.  All the users of Project X would be members of the Global Group "Project X".  All the Admin Staff members would be members of the Global Group "Admin Staff".  All the Interns would be members of the Global Group "Interns".

When there is a lot of domain level changes occurring, and cross domain group changes occurring, you'd create a Universal Group to simplify the assignments of rights.  For example, if you create a new domain for projects as they spin up, and every new domain has an administrative share that all the admin staff need to access... you'd take most of the previous steps, but instead of making the global groups members of the domain local group, you'd make all the global groups members of a universal group (say, "All Admin Staff"), and that "All Admin Staff" universal group would be a member of Domain Local Group in each domain on which rights are assigned.  (That way, as changes occur at the domain level, you only need to make changes to groups in the new domain, and to the appropriate Universal Groups.

Of course, that's only how they should be used.  In a lot of cases, especially small environments, I've seen folks just use Global Groups or Universal Groups for everything and not worry about it.  (And in those cases, they put users in the one group and assign rights directly to that same group.)
0
 

Author Closing Comment

by:Sanjeev jha
ID: 41885678
Thanks for answer, really it helpled me.
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question