QQ231273 states: "Domain Local groups should not be used to assign permissions on Active Directory objects, because Domain Local groups cannot be evaluated in other domains, and parts of most Active Directory objects get replicated to other domains in the form of the GC. Access restrictions placed on Active Directory objects that are based on Domain Local group membership have no effect on GC queries that take place in groups other than the domain in which the Domain Local group originated."
What the KB article doesn't provide is concrete examples of the dangers of assigning Domain Local Groups permissions on directory objects. Nor does it provide practical advice on what to use instead. Assigning permissions directly to Global Groups doesn't seem very sensible given their domain-wide scope (it also goes against the standard AGLP model). I suppose Universal Groups could be an option. What is everyone else doing? Tony List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
