QQ231273 states:

"Domain Local groups should not be used to assign permissions on Active Directory
objects, because Domain Local groups cannot be evaluated in other domains, and
parts of most Active Directory objects get replicated to other domains in the
form of the GC. Access restrictions placed on Active Directory objects that are
based on Domain Local group membership have no effect on GC queries that take
place in groups other than the domain in which the Domain Local group
originated."

What the KB article doesn't provide is concrete examples of the dangers of assigning 
Domain Local Groups permissions on directory objects.  Nor does it provide practical 
advice on what to use instead.  Assigning permissions directly to Global Groups 
doesn't seem very sensible given their domain-wide scope (it also goes against the 
standard AGLP model).  I suppose Universal Groups could be an option.

What is everyone else doing?

Tony


List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to