4 Groups Flashcards
What usages of groups there are?
For the role-based management there are:
Role groups
Rule groups
What is a shadow group?
A group that contains, as members, the users in an OU.
What does the role group do?
These groups contain users, computers, and other role groups based on common business characteristics such as location and job type.
What does rule groups do?
These groups, referred to as rule groups, define how an enterprise resource is managed.
List all the types of group scopes.
Local
Domain Local
Universal
Global
Describe the properties of Local groups.
It is restricted only to the local machine.
Can include any security principals from the domain. Users, computers, global and universal groups from any domain in the forest. Users, computers and global groups from any trusted domain.
Describe the properties of Domain Local groups.
Replicated to every DC in the forest.
Can include any security principals from the domain. Users, computers, global and universal groups from any domain in the forest. Users, computers and global groups from any trusted domain.
Can be added to ACLs on any resource on any domain member. Can be a member of other domain local groups or even local groups.
Describe the properties of Global groups.
Replicated to every DC in the forest.
Can include only users, computers, and global groups from the same domain.
Can be a member of any domain local or universal group in the domain or the forest. Can also be in any domain local group in a trusting domain. Can be added to ACLs in the domain, in the forest, or in trusting domains.
Describe the properties of Universal groups.
Replicated in GC across the forest.
Can include users, global groups, and other universal groups from any domain in the forest.
Can be a member of a universal group or domain local group anywhere in the forest. Can be used for permission assignments.
What are the default groups in AD domain?
Enterprise Admins Schema Admins Administrators Domain Admins Server Operators Account Operators Backup Operators Print Operators
What are the special identities in AD domain?
Anonymous Logon
Authenticated Users
Interactive
Network