Solved

Windows server 2008

Posted on 2016-11-07
5
46 Views
Last Modified: 2016-11-13
Hi,

Please help me to understand in real scenario and how to use it.

1: Differences between Global , Domain local, and universal group and how/where to use it.

Warm Regards
Sanjeev Jha.
0
Comment
Question by:Sanjeev jha
  • 3
  • 2
5 Comments
 
LVL 30

Expert Comment

by:Rich Weissler
ID: 41877621
Ah, Group Scope and role based access controls.  :-) The differences are important if you have trusts between domains and you're working with forests, etc.

Domain Local Groups can be used to assign rights only to objects in the local domain, but members can be in any domain.
Global Groups can be used to assign rights anywhere, but members have to be in the local domain.
Universal Groups can be used to assign rights anywhere, and can have members from any domain.

NORMALLY, If you are assigning permissions/rights to a share, or a folder, or to an OU in your domain, or to determine who can enroll for a particular type of certificate -- you'd grant that to a Domain Local Group.  In each domain in which there will be consumers who need access to that object -- you'd create a global group and put the relevant users in the global group.  Then you'd simply make the global groups as members of the domain local group.

The abbreviation AGDLP spells things in the opposite direction, but the result is the same... using  "account, global, domain local, permission" and is contrasted by AGUDLP (for "account, global, universal, domain local, permission").  That wikipedia article goes further into explaining role based access controls.
0
 

Author Comment

by:Sanjeev jha
ID: 41877647
Sir: Thanks for your support but I need through Example which can clear my doubt and it will help easily understand.


Warm Regards
Sanjeev Jha.
0
 
LVL 30

Expert Comment

by:Rich Weissler
ID: 41877713
Lets say you have a common administrative share to which your administrative staff needs access.
First, create a Domain Local Group in the same domain as the file server resource... in this case "SHR-AdminCommon".
I would grant that group Read and Change permissions to the share, and Read/Write access to the NTFS folder.
I would then create a Global Group in each domain which will have administrative staff user accounts.  I might call the group "Admin Staff".
Into each of those Global Groups, I'd place my admin staff user accounts.
Into the Domain Local Group (SHR-AdminCommon), I'd make each of the separate Admin Staff Global Groups a member.
0
 
LVL 30

Accepted Solution

by:
Rich Weissler earned 500 total points
ID: 41877760
So, when should you use each type of group?

When assigning rights or permissions -- assign the rights or permissions to a Domain Local Group.  Delegating the ability to perform password changes to users in specific OUs, for example... or permissions to Shares or Folders...

When grouping users, you'll (usually) use Global Groups.  All the users of Project X would be members of the Global Group "Project X".  All the Admin Staff members would be members of the Global Group "Admin Staff".  All the Interns would be members of the Global Group "Interns".

When there is a lot of domain level changes occurring, and cross domain group changes occurring, you'd create a Universal Group to simplify the assignments of rights.  For example, if you create a new domain for projects as they spin up, and every new domain has an administrative share that all the admin staff need to access... you'd take most of the previous steps, but instead of making the global groups members of the domain local group, you'd make all the global groups members of a universal group (say, "All Admin Staff"), and that "All Admin Staff" universal group would be a member of Domain Local Group in each domain on which rights are assigned.  (That way, as changes occur at the domain level, you only need to make changes to groups in the new domain, and to the appropriate Universal Groups.

Of course, that's only how they should be used.  In a lot of cases, especially small environments, I've seen folks just use Global Groups or Universal Groups for everything and not worry about it.  (And in those cases, they put users in the one group and assign rights directly to that same group.)
0
 

Author Closing Comment

by:Sanjeev jha
ID: 41885678
Thanks for answer, really it helpled me.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
In-place Upgrading Dirsync to Azure AD Connect
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question