MCITP 70-640: Active Directory Groups

preview_player
Показать описание
Windows allows the creation of groups which simplifies permissions assignment for users. This video looks at how to use groups in Windows and also looks at the basics of how to use role based access control, one strategy used to simplify group administrator in a domain.

Groups
Each group that is created has a security identifier or SID associated with it. This SID is added to the local access list for the resource that you are controlling access to. A group can be created that does not have a SID that is used for distribution lists. These groups are covered in the next video.

Nesting
When you place one group inside another group, it is called nesting. Nesting also allows two or more groups to be placed in the same group. This essentially means that administration could be divided between two or more administrators. When administration is separated like this it is often referred to as granular control because each administrator has administrative control over a small part of the whole effects of that group that contains the other groups
Using nesting, you could create groups for the users in New York, Washington and London. Using nesting you could create a group called All_Users in which the groups for each location could be put in. Nesting can also be broken down further. For example you could divide New York users into two groups called NY_Sales and NY_Marketing. These two groups could be placed in NY_Users and this group placed in All_Users. If you wanted to create a group for All_Sales users, you could place all the sales groups from each location in this group. Notice using nesting like this means that a new user only needs to be put into the one group. Once in this group, membership of the other groups like the All_Users and All_Sales group through nesting is also achieved, allowing simple administration.

Role based access control
Role based access control is a strategy of group management generally used in large enterprises. This approach is generally used in companies with more than 500 employees. The approach involves not adding the user or users directly to the resource. In order to grant access, another group is created and assigned permissions to the resource. For example, if you had a share called general you would create two groups called general_share_modify and general_share_read. These would be assigned to the general share and given the required access.

In order to give users access to a resource, groups containing users are added to the groups based on the roles in the organization. For example, if all sales users need modify access, the sales group would be added to general_share_modify. If the marketing group needed read access, the marketing group containing all the marketing users would be added to group general_share_read. If a user were to change departments, for example, from sales to marketing, the user's account would simply be removed from the sales group and added to the marketing group. When assigning roles to a user, or removing roles, the resource never needs to be modified.

References
"MCTS 70-640 Configuring Windows Server 2008 Active Directory" Microsoft Press, pg 141-144
Рекомендации по теме
Комментарии
Автор

Your videos are truly an act of great altruism. Knowledge shared is knowledge grown. I can only say thank you from my heart and wish you the best in everything.

sirhumanoid
Автор

I almost skipped this because I thought I knew enough about groups... Until I decided not to. Then I learnt about nested groups/role based access control! The playlist is just awesome!

BijouBakson
Автор

I am working in IT field for past 10 years, and I have never seen such a detailed explanation of how groups work. So nice tutorial. All of your videos regarding AD are so on the spot, detailed, simple to understand. I wish you would continue to your purpose of making FREE Training Videos on IT. I see you stopped. Please continue. Rather make a Patreon page so that we can donate, and people can learn in free. The tutor who created this AD lessons is awesome. Hats off! So knowledgeable and so simple way of making things clear.

petersmith
Автор

Thanks for leaving a comment. It good to hear that your like are videos.

itfreetraining
Автор

Setting up a server for a company, your videos always have helped me. Thank you

msmit
Автор

Thank you. Good luck with your study and passing the exam.

itfreetraining
Автор

Thanks very much. Glad you like the course.

itfreetraining
Автор

Thanks very much and please thank your lecturer.

itfreetraining
Автор

Great primary or alternative learning program!Thanks to you guys! God bless!

dandeegarcia
Автор

There is a set of groups that apply to all Domain Controllers, however these are domain wide only and do not effect the forest. It all depends what you are trying to achieve in order to work out how to set it up.

itfreetraining
Автор

Thanks very much, glad we could help.

itfreetraining
Автор

Excellent videos, very helpful and useful. Even my lecturer from my course recommended all of them as well,

RaeborQuark
Автор

Changes are replicated to all Domain Controllers in the domain. Some changes are replicate to every domain controller in the forest.

itfreetraining
Автор

Excellent course, I watched lot of AD course videos of yours, all are excellent and also there is course on AD group scopes ..

tsramUT
Автор

Hi, i have a question, can i block a user from a local group to use a color printer? but the others users from local can use the printer?

CocoFelix
Автор

We have a couple released so far. If you go to the web site, have a look under free courses.

itfreetraining
Автор

Thank you.. its clear.... your good name sir...

ESWARANM-Techguy
Автор

In the example why did you use Invoice_Modify vs. Invoice_Write?

plcnoob
Автор

Hi Sir, Very good and informative videos.. These courses are available for 2012 Server Active directory as well? Please share me the link....

sachinkapoor
Автор

when made change to AD it will reflect the changes through out the domain .why we need to go for every servers to make changes ....????..

puneethpenetrator