webForumDet fria alternativet

Lokala resp globala grupper i Windows domän

Windows

3 svar · 800 visningar · startad av Sunix

Medlem sedan juli 2004310 inlägg
Frågan#1

Hej!

En lokal grupp i domänen(skapad i AD) används för att ge rättigheter till mappar, filer, skrivare osv... lokalt på servern t.ex.

En global grupp i domänen skapas för att organisera användare i domänen.

Den globala gruppen används sedan i den lokala gruppen för att ge användarna i globala gruppen tillgång till de lokala resurserna.

Eller hur?

Vad är anledningen till lokala gruppen (domän).
Man kan ju ge rättigheterna direkt till den globala gruppen.

EX:
Jag skapar en filresurs på min 2003server och ger den globala gruppen Produktion behörighet att ansluta och rättighet att skriva till...

Hjälp mig att bena!

Medlem sedan dec. 199917 055 inlägg
#2

http://www.webforum.nu/showthread.php?s=&postid=956850#post956850

Anledningen är nog främst att det ska vara lättare att överblicka och därigenom blir säkrare. En lokal grupp för varje rättighet. En global grupp som samlar ihop rättigheterna. Medlemmar läggs i den globala gruppen.

Medlem sedan juli 2004310 inlägg
#3

Det här med alla fattar jag inte! Om jag ger alla behörighet så behöver jag ingen grupp alls?!?!?!

Det är klart att har jag t.ex. 40 filresurser och 20 globala grupper som ska ha tillgång till filresurserna så får jag gå in i varje resurs och lägga till 20 globala grupper = 40*20 = 800

har jag däremot lagt en lokal grupp i varje filresurs så räcker det med att lägga till globala grupperna i den lokala = 20*1+20 = 40

Hmm, lite skillnad eller hur. Tänker jag rätt????????

Medlem sedan dec. 2000485 inlägg
#4

Konstruktionen är inte tillverkad för att du skall få mer/mindre att göra utan om hur access till resurser sker. Vid designen såg inte utveklarna till enbart singel domäner utan även för tillfällen med domäner i "trust-relations".

Kan inte förklara det bra själv utan saxar från webben:

Local Groups
A local group describes access permissions to resources that are local to the domain. The scope of a local group is limited to the domain in which it was created. It can’t describe access permissions to resources outside of this domain. Moreover, you can’t see or use a local group outside of its home domain. However, you can include a user account from another domain within a local group as long as the other domain is trusted by the local domain. This capability enables you to grant resource access to users in other domains.

Global Groups
A global group, on the other hand, is simply a list of users from a specific domain. A global group includes only user accounts from within the domain in which the global group was created. A global group can’t contain any other groups, and you can’t assign access permissions to it.

Global vs. Local Groups
Think of a global group as a building block used in other domains to build local groups. Global groups provide a handy means of exporting a group of users in a domain to other domains on the network. When you define a local group within a domain, you can include a global group of users within that local group. The resource access permissions you assign to the local group are granted to the users in the global group even though those users exist in a different domain.

As long as the domain that defines a local group trusts the domain that defines the global group, the global group can be added to the local group and users within the global group have the same access permissions as other members of the local group.

Tip: Consider using global groups exclusively as the building blocks of your local groups. Remember that local groups can contain global groups defined in the local domain and in trusted domains. If your local groups are composed entirely of global groups, whenever you change the membership of a global group, the local groups that contain it are automatically updated.

256 ms totalt · 4 externa anrop · v20260731065814-full.1dc6f849
119 ms — deklarationer (db)
0 ms — hämta statistik (cache)
133 ms — hämta tråd, inlägg och bilagor (db)
120 ms — ändringar (db)