Welcome to ServerForumz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Ability to list groups member of a trusted domain is in

 
   Windows Server (Home) -> Windows Server Security RSS
Next:  what is rsyncd service ?  
Author Message
Mike Matheny

External


Since: Feb 03, 2006
Posts: 29



(Msg. 1) Posted: Wed Jul 26, 2006 11:30 am
Post subject: Ability to list groups member of a trusted domain is in
Archived from groups: microsoft>public>windows>server>security (more info?)

We have around 10 trusted domains that we sometimes add users from into our
domain local groups. When a user from a trusted domain leaves, we need a way
to find out what groups in OUR domain he is a member of and remove him I
have not been able to find any way to do this (short of going through all
1000 of our groups manually!!), so that is why I am asking the experts!

--

Mike Matheny

 >> Stay informed about: Ability to list groups member of a trusted domain is in 
Back to top
Login to vote
Roger Abell [MVP]

External


Since: May 04, 2004
Posts: 559



(Msg. 2) Posted: Wed Jul 26, 2006 4:28 pm
Post subject: Re: Ability to list groups member of a trusted domain is in [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

That is, or certainly can be, a tough nut to crack.
What I try to use is:
1. never grant to users, not anything, not ever
2. allow users into a subset of the groups only
(I think of these as principal groups)
3. use grants for rights, resources, etc. with
groups defined for those purposes
(I think of these as resource groups)
4. use principal groups no where except to
populate resource groups
5. have and uphold a group naming convention so that
it is clear what group is a principal group, and what
the uses of the resource groups are (and use them
only that way)
Then, there is a limited subset of groups that need to
be periodically examined for accounts, and as a side
effect looking at the resource groups tells one immediately
what categories of users have that access.
For the examination I use script.
If one does not start out right one can quickly get a mess
on one's hands.

--
Roger Abell
Microsoft MVP (Windows Server : Security)

"Mike Matheny" <mikemathenyathoustondotrrdotcom> wrote in message

> We have around 10 trusted domains that we sometimes add users from into
> our domain local groups. When a user from a trusted domain leaves, we need
> a way to find out what groups in OUR domain he is a member of and remove
> him I have not been able to find any way to do this (short of going
> through all 1000 of our groups manually!!), so that is why I am asking the
> experts!
>
> --
>
> Mike Matheny
>
>
>

 >> Stay informed about: Ability to list groups member of a trusted domain is in 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Domain Local Groups and Member Servers - Some folks I know are advocating doing away with the use of local groups on member servers. They would assign rights on member severs directly to domain local groups rather than to local groups on the member server. Can I get a sanity check? Am all we...

cannot access domain local groups from a member server! - .. - Hi I just set up a new Windows 2000 server to do some file/print. I didn't install it as a DC as I didn't see the need for yet another (we have 3), and it will make the server and network a bit more efficient, and so decided to go down the route of..

Authenticating from a trusted wk2 domain to a w2k3 domain. - I have 2 domains in separate forests. One domain is on W2k, the other on W2k3. The W2k3 domain trusts the W2k domain. Windows Media Services is on the W2k3 domain for streaming video. Everyone must authenticate to view the streaming video. Users from th...

Viewing Trusted Domain Group Memberships - In our Windows 2003 AD domain, we have two domain trees in a single forest. We have a scenario where we add users from one domain into universal distribution groups of the other domain. That works as expected. When we look at the members of the..

Domain Controller Computer Trusted For Delegation? - I have been playing about with 'Trusted For Delegation' setting for computers in my test Windows 2003/XP Professional domain. I have now achieved what I wanted to achieve and have returned all the computers to their original settings. The setting for...
   Windows Server (Home) -> Windows Server Security All times are: Pacific Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]