One specific scenario I have found where this has an impact is the following.
You may wish for security reasons to deny "read" permissions on a particular OU. If you use a domain local group to set these permissions, the OU contents will still be visible when viewing the object on a Global Catalog (port 3268) that is not local to the domain in which that OU (and the domain local group) resides. If you query a Global Catalog in the same domain as the OU then the restriction applies and the OU contents are not visible. If you query any DC directly (port 389) the restriction also applies, irrespective of domain. In this scenario, assigning permissions directly to a universal group resolves the problem. Tony -----Original Message----- From: Tony Murray [mailto:[EMAIL PROTECTED]] Sent: 04 December 2001 15:20 To: [EMAIL PROTECTED] Subject: [ActiveDir] Domain local groups QQ231273 states: "Domain Local groups should not be used to assign permissions on Active Directory objects, because Domain Local groups cannot be evaluated in other domains, and parts of most Active Directory objects get replicated to other domains in the form of the GC. Access restrictions placed on Active Directory objects that are based on Domain Local group membership have no effect on GC queries that take place in groups other than the domain in which the Domain Local group originated." What the KB article doesn't provide is concrete examples of the dangers of assigning Domain Local Groups permissions on directory objects. Nor does it provide practical advice on what to use instead. Assigning permissions directly to Global Groups doesn't seem very sensible given their domain-wide scope (it also goes against the standard AGLP model). I suppose Universal Groups could be an option. What is everyone else doing? Tony List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
