Click here to get back home

Nesting domain groups under local groups

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Nesting domain groups under local groups fpbear 03-18-2007
Posted by fpbear on March 18, 2007, 3:56 am
Please log in for more thread options
I am wondering whether the following is good design practice. We have an
application that is locked down using domain GPOs, including setting
permissions on the user data files. Sometimes the users will travel and
attach these laptops to other domains (separate domains, not part of a
forest or trust). They log into these domains with another user account,
but they lose access to their data files because the SID for the account on
the file ACL is different on this new domain. So we are thinking of
creating local custom goups for the application and then nesting the
application's custom domain groups under them. When the user joins a
different domain then the domain admin just adds the domain group under the
local group. In this design, the local custom group is the group added to
the file permission. The application also checks to see if the domain user
is a member of the local group (via nested domain group) before access to
features. Would this work?



Posted by Roger Abell [MVP] on March 18, 2007, 9:06 am
Please log in for more thread options
That is probably how most people would do it, if they were
letting their machines change domains like that (which most
people would not want to allow).

>I am wondering whether the following is good design practice. We have an
> application that is locked down using domain GPOs, including setting
> permissions on the user data files. Sometimes the users will travel and
> attach these laptops to other domains (separate domains, not part of a
> forest or trust). They log into these domains with another user account,
> but they lose access to their data files because the SID for the account
> on
> the file ACL is different on this new domain. So we are thinking of
> creating local custom goups for the application and then nesting the
> application's custom domain groups under them. When the user joins a
> different domain then the domain admin just adds the domain group under
> the
> local group. In this design, the local custom group is the group added to
> the file permission. The application also checks to see if the domain
> user
> is a member of the local group (via nested domain group) before access to
> features. Would this work?
>
>



Similar ThreadsPosted
Local Users & Groups Migration April 5, 2006, 9:19 am
server migration/local Groups August 2, 2006, 3:47 pm
Re: looking for individuals to run local security groups March 4, 2008, 5:17 pm
Domain Local Security vs Global Security vs Universal Security Groups October 16, 2006, 1:26 pm
AD administrators and domain admins groups April 25, 2006, 12:26 pm
Ability to list groups member of a trusted domain is in July 26, 2006, 12:30 pm
Security Groups ... Where June 8, 2005, 4:01 pm
Restricted Groups July 3, 2006, 6:43 pm
RE: Default Security Groups February 21, 2007, 3:24 am
RE: Default Security Groups March 27, 2007, 7:01 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap