Anledningen är nog främst att det ska vara lättare att överblicka och därigenom blir säkrare. En lokal grupp för varje rättighet. En global grupp som samlar ihop rättigheterna. Medlemmar läggs i den globala gruppen.
Det här med alla fattar jag inte! Om jag ger alla behörighet så behöver jag ingen grupp alls?!?!?!
Det är klart att har jag t.ex. 40 filresurser och 20 globala grupper som ska ha tillgång till filresurserna så får jag gå in i varje resurs och lägga till 20 globala grupper = 40*20 = 800
har jag däremot lagt en lokal grupp i varje filresurs så räcker det med att lägga till globala grupperna i den lokala = 20*1+20 = 40
Hmm, lite skillnad eller hur. Tänker jag rätt????????
Konstruktionen är inte tillverkad för att du skall få mer/mindre att göra utan om hur access till resurser sker. Vid designen såg inte utveklarna till enbart singel domäner utan även för tillfällen med domäner i "trust-relations".
Kan inte förklara det bra själv utan saxar från webben:
Local Groups
A local group describes access permissions to resources that are local to the domain. The scope of a local group is limited to the domain in which it was created. It can’t describe access permissions to resources outside of this domain. Moreover, you can’t see or use a local group outside of its home domain. However, you can include a user account from another domain within a local group as long as the other domain is trusted by the local domain. This capability enables you to grant resource access to users in other domains.
Global Groups
A global group, on the other hand, is simply a list of users from a specific domain. A global group includes only user accounts from within the domain in which the global group was created. A global group can’t contain any other groups, and you can’t assign access permissions to it.
Global vs. Local Groups
Think of a global group as a building block used in other domains to build local groups. Global groups provide a handy means of exporting a group of users in a domain to other domains on the network. When you define a local group within a domain, you can include a global group of users within that local group. The resource access permissions you assign to the local group are granted to the users in the global group even though those users exist in a different domain.
As long as the domain that defines a local group trusts the domain that defines the global group, the global group can be added to the local group and users within the global group have the same access permissions as other members of the local group.
Tip: Consider using global groups exclusively as the building blocks of your local groups. Remember that local groups can contain global groups defined in the local domain and in trusted domains. If your local groups are composed entirely of global groups, whenever you change the membership of a global group, the local groups that contain it are automatically updated.
262 ms totalt · 4 externa anrop · v20260731065814-full.1dc6f849