Đang chuẩn bị liên kết để tải về tài liệu:
The Best Damn Windows Server 2003 Book Period- P49

Đang chuẩn bị nút TẢI XUỐNG, xin hãy chờ

The Best Damn Windows Server 2003 Book Period- P49:The latest incarnation of Microsoft’s server product,Windows Server 2003, brings many new features and improvements that make the network administrator’s job easier.This chapter will briefly summarize what’s new in 2003 and introduce you to the four members of the Windows Server 2003 family: the Web Edition, the Standard Edition, the Enterprise Edition, and the Datacenter Edition. | 446 Chapter 11 Creating User and Group Strategies Figure 11.9 AGDLP in a Multiple Domain Forest Moving all of the domains in the forest to the Windows 2000 native or Windows Server 2003 functional level greatly reduces the complexity. Just as we saw in the previous section when a new benefits user joins the company the only group his or her account needs to be made a member of is the Benefits global group in his or her regional domain. Again this is because the Benefits global group is nested in the HR global group. The real power in a multiple domain environment however comes in the ability to use universal security groups.You no longer have to add each HR global group into the Global_HR_Resources domain local group. Instead you can add all of the HR global groups into a universal group called ALL_HR.You then add this group into the Global_HR_Resources DLG. These group memberships are shown in Figure 11.10. When universal groups enter the design we are using the AGGUDLP model sometimes abbreviated AGUDLP where U represents Universal group.This model means Accounts should be placed into Global groups that can be placed into other Global groups and or Universal groups and then into Domain Local groups which are added to ACLs and granted Permissions to resources. Creating User and Group Strategies Chapter 11 447 Figure 11.10 AGGUDLP in a Multiple Domain Forest While this might look like a similar amount of work when compared with Figure 11.9 the real power of this design becomes evident when you attempt to grant all HR users access to another resource such as a printer in Asia. In this case you simply need to create a new DLG and grant the print permission for the printer in the Asia domain to that group. In Figure 11.11 the group is called HR_Print_Asia.You then simply add the All_HR universal group to the HR_Print_Asia domain local group. Imagine what the diagram would look like if you couldn t use a universal group and how much more work would be involved.You .

TAILIEUCHUNG - Chia sẻ tài liệu không giới hạn
Địa chỉ : 444 Hoang Hoa Tham, Hanoi, Viet Nam
Website : tailieuchung.com
Email : tailieuchung20@gmail.com
Tailieuchung.com là thư viện tài liệu trực tuyến, nơi chia sẽ trao đổi hàng triệu tài liệu như luận văn đồ án, sách, giáo trình, đề thi.
Chúng tôi không chịu trách nhiệm liên quan đến các vấn đề bản quyền nội dung tài liệu được thành viên tự nguyện đăng tải lên, nếu phát hiện thấy tài liệu xấu hoặc tài liệu có bản quyền xin hãy email cho chúng tôi.
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.