Options

Group Management Strategy - help...

Daniel333Daniel333 Member Posts: 2,077 ■■■■■■□□□□
Pre-Test....

I ran into this question and I just have no idea where to turn to better understand this type of question...

The Contoso, Ltd Active Directory domain includes one Windows Server 2003 domain controller and two Windows NT 4.0 domain controllers. There are fewer than 150 users in the domain. The company does not plan to add domains in the future. Which user group management strategy is appropriate for this organization?

A G L P
A DL P
A G U DL P
A G DL P

I am lost on this one, not sure what I should be doing. I see the chart explaining that DL = Domain Local, but I really don't see what a domain local, universal and global groups are for? They seem to do the same thing.

What do you think?
-Daniel

Comments

  • Options
    dynamikdynamik Banned Posts: 12,312 ■■■■■■■■■□
    [edit]
    Ignore me on this one. Mishra nailed it.

    This is still a good link though:
    The groups vary based on where members can be assigned from and where the groups can be assigned resources: Groups in Server 2003?
  • Options
    MishraMishra Member Posts: 2,468 ■■■■□□□□□□
    Accounts are placed into Global Groups, which are placed into Universal Groups, which are placed into Domain Local Groups where Permissions are assigned


    They are trying to teach you that you don't need to use universal/global groups if you have a simple environment. So use A DL P



    However in the real world you should set your domain up with A G DL P to make it simple if you ever need to go to a multi domain environment.
    My blog http://www.calegp.com

    You may learn something!
  • Options
    Daniel333Daniel333 Member Posts: 2,077 ■■■■■■□□□□
    Thanks!
    -Daniel
  • Options
    MishraMishra Member Posts: 2,468 ■■■■□□□□□□
    Dunno if this makes sense to you but I sometimes memorize this as

    A GULP

    accounts - global - universal - local - permissions
    My blog http://www.calegp.com

    You may learn something!
  • Options
    famosbrownfamosbrown Member Posts: 637
    I don't know...that might be one of those trick questions since it says there is a domain with Windows server 2003 and Windows NT domain controllers. This would lead me to assume that the functional level would be Windows Server 2003 Interim, so you would not be able to use Universal Groups except for Distribution Groups, so I would choose A G DL P.
    B.S.B.A. (Management Information Systems)
    M.B.A. (Technology Management)
  • Options
    rjbarlowrjbarlow Member Posts: 411
    This topic is the one because I decided to postpone my exam.
    Pork 3
    Maindrian's music

    WIP: 70-236, 70-293 and MCSE.
  • Options
    RevenueRevenue Member Posts: 130
    My instructor told it to me this way :P seemed to stick fine..


    All Girls Usually DoLike Parties

    accounts - groups - Universal - Domain Local - Permissions


    Might help someone else,
  • Options
    DragonNOA1DragonNOA1 Member Posts: 149 ■■■□□□□□□□
    Though I cant seem to find any documentation on it, if you have NT 4.0 domain controllers you must use A G L P b/c NT 4.0 does not have domain local groups but only local groups. You are really assigning global groups to local groups. Can anyone confirm this? This is what I was taught about NT 4.0 and a mixed mode domain.
    The command line, an elegant weapon for a more civilized age
  • Options
    famosbrownfamosbrown Member Posts: 637
    DragonNOA1 wrote:
    Though I cant seem to find any documentation on it, if you have NT 4.0 domain controllers you must use A G L P b/c NT 4.0 does not have domain local groups but only local groups. You are really assigning global groups to local groups. Can anyone confirm this? This is what I was taught about NT 4.0 and a mixed mode domain.

    Yes...I believe you are correct. In Mixed Mode, the Domain Local Groups may just apply to the Domain Controllers and not Members Servers. I remember reading about this when I was studying in the past, but I can't recall any references or anything...or I could have just misinterpreted what I read icon_lol.gif .
    B.S.B.A. (Management Information Systems)
    M.B.A. (Technology Management)
  • Options
    PashPash Member Posts: 1,600 ■■■■■□□□□□
    The technotes are fecking awesome for group management and where you might wan't to use universal groups in native mode etc. Suggest you take a look if you havent :)
    DevOps Engineer and Security Champion. https://blog.pash.by - I am trying to find my writing style, so please bear with me.
Sign In or Register to comment.