One specific scenario I have found where this has an impact is the following.

You may wish for security reasons to deny "read" permissions on a particular OU.  If 
you use a domain local group to set these permissions, the OU contents will still be 
visible when viewing the object on a Global Catalog (port 3268) that is not local to 
the domain in which that OU (and the domain local group) resides.  If you query a 
Global Catalog in the same domain as the OU then the restriction applies and the OU 
contents are not visible.  If you query any DC directly (port 389) the restriction 
also applies, irrespective of domain.

In this scenario, assigning permissions directly to a universal group resolves the 
problem.

Tony

-----Original Message-----
From: Tony Murray [mailto:[EMAIL PROTECTED]]
Sent: 04 December 2001 15:20
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Domain local groups


QQ231273 states:

"Domain Local groups should not be used to assign permissions on Active
Directory
objects, because Domain Local groups cannot be evaluated in other domains,
and
parts of most Active Directory objects get replicated to other domains in
the
form of the GC. Access restrictions placed on Active Directory objects that
are
based on Domain Local group membership have no effect on GC queries that
take
place in groups other than the domain in which the Domain Local group
originated."

What the KB article doesn't provide is concrete examples of the dangers of
assigning Domain Local Groups permissions on directory objects.  Nor does it
provide practical advice on what to use instead.  Assigning permissions
directly to Global Groups doesn't seem very sensible given their domain-wide
scope (it also goes against the standard AGLP model).  I suppose Universal
Groups could be an option.

What is everyone else doing?

Tony

List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to