> If so, what are the alternatives / suggestions
open to me?
well,
the first suggestion would be not to implement a multi-domain forest if you can.
Try to do everything with OUs. If you can't and you're going to
"hide" data in AD that you need to have accessible in the GC, then use UGs to
grant the required permissions. This will work for direct membership in the UGs
or nested GGs.
Last
warning: you do need to be careful with nesting GGs into UGs for other reasons
=> if membership of the UGs is expanded by other apps to determine their
membership (e.g. by Exchange Servers when determining recipients of a
distribution list), the nested GGs will not be a good thing. For similar reasons
as desribed above, the GC of DOMB will not know who is a member of the GG in
DOMA that is nested into a UG in DOMB - as such the Exchange server can't fully
expand the group and mail delivery will fail. So, for many circumstances it is
benefitial to populate the UGs directly with the users (or other
UGs).
Enough for today.
/Guido
It's Friday afternoon and I think I need more sugar
and/or caffeine :)
I've recently read in several places how the use of
domain local groups (DLGs) could represent an issue when used to permission GC
replicated domain data.
For example - this an excerpt from a MS
article:
"Special security consideration should be given
when specifying permissions on domain data that is also replicated to the global
catalog. When a user connects to a global catalog, an impersonation token is
created for the user, which is used in subsequent access control decisions on
the global catalog. The user's universal, global and domain local group
memberships are represented in this token. However, only domain local groups
from the domain that the domain controller hosting the global catalog (to which
the user has connected) belongs to and of which the user is a member show up in
the user's token. Domain local groups in the user's domain (and in other
domains) of which the user is a member do not show up in the access
token."
I'm trying to figure out if this represents an issue
to me in my (proposed) regional multi-domain environment or not.
We are currently planning to use DLGs for
permissioning AD data as well as server based data. We planned to then nest
global groups (GGs) into these DLGs from various domains in the forest. Will
such a scenario be affected by the issue described above? If so, what are the
alternatives / suggestions open to me?
Can someone offer an example of when the above would
represent a true issue? [Assuming my scenario above is not a good
example.]
Thanks,
neil
___________________________
Neil Ruston
Global Technology
Infrastructure
Nomura
International plc
PLEASE READ: The
information contained in this email is confidential and
intended for the
named recipient(s) only. If you are not an intended
recipient of this
email please notify the sender immediately and delete your
copy from your
system. You must not copy, distribute or take any further
action in reliance
on it. Email is not a secure method of communication and
Nomura International
plc ('NIplc') will not, to the extent permitted by law,
accept
responsibility or liability for (a) the accuracy or completeness of,
or (b) the presence
of any virus, worm or similar malicious or disabling
code in, this
message or any attachment(s) to it. If verification of this
email is sought then
please request a hard copy. Unless otherwise stated
this email: (1) is
not, and should not be treated or relied upon as,
investment research;
(2) contains views or opinions that are solely those of
the author and do
not necessarily represent those of NIplc; (3) is intended
for informational
purposes only and is not a recommendation, solicitation or
offer to buy or sell
securities or related financial instruments. NIplc
does not provide
investment services to private customers. Authorised and
regulated by the
Financial Services Authority. Registered in England
no. 1550505 VAT No.
447 2492 35. Registered Office: 1 St Martin's-le-Grand,
London, EC1A 4NP. A
member of the Nomura group of companies.
PLEASE READ: The
information contained in this email is confidential and
intended for the
named recipient(s) only. If you are not an intended
recipient of this
email please notify the sender immediately and delete your
copy from your
system. You must not copy, distribute or take any further
action in reliance
on it. Email is not a secure method of communication and
Nomura International
plc ('NIplc') will not, to the extent permitted by law,
accept
responsibility or liability for (a) the accuracy or completeness of,
or (b) the presence
of any virus, worm or similar malicious or disabling
code in, this
message or any attachment(s) to it. If verification of this
email is sought then
please request a hard copy. Unless otherwise stated
this email: (1) is
not, and should not be treated or relied upon as,
investment research;
(2) contains views or opinions that are solely those of
the author and do
not necessarily represent those of NIplc; (3) is intended
for informational
purposes only and is not a recommendation, solicitation or
offer to buy or sell
securities or related financial instruments. NIplc
does not provide
investment services to private customers. Authorised and
regulated by the
Financial Services Authority. Registered in England
no. 1550505 VAT No.
447 2492 35. Registered Office: 1 St Martin's-le-Grand,
London, EC1A 4NP. A
member of the Nomura group of companies.
PLEASE READ: The information contained in this email is confidential and
intended for the named recipient(s) only. If you are not an intended
recipient of this email please notify the sender immediately and delete your
copy from your system. You must not copy, distribute or take any further
action in reliance on it. Email is not a secure method of communication and
Nomura International plc ('NIplc') will not, to the extent permitted by law,
accept responsibility or liability for (a) the accuracy or completeness of,
or (b) the presence of any virus, worm or similar malicious or disabling
code in, this message or any attachment(s) to it. If verification of this
email is sought then please request a hard copy. Unless otherwise stated
this email: (1) is not, and should not be treated or relied upon as,
investment research; (2) contains views or opinions that are solely those of
the author and do not necessarily represent those of NIplc; (3) is intended
for informational purposes only and is not a recommendation, solicitation or
offer to buy or sell securities or related financial instruments. NIplc
does not provide investment services to private customers. Authorised and
regulated by the Financial Services Authority. Registered in England
no. 1550505 VAT No. 447 2492 35. Registered Office: 1 St Martin's-le-Grand,
London, EC1A 4NP. A member of the Nomura group of companies.