How do you do it? Security Groups/Shadow Groups
i'm curious know how other organisations around problem.
- my user accounts sit in ou structured department (development, finance, it, sales, services)
- each department has matching security group (gen_development, gen_finance, gen_it, etc.) these security groups have required permissions starting 'base'.
- users in each department members of gen_ group obtain base set of permissions required department.
when user moves departments, need loose base permissions department , gain base permissions new department. achieved changing gen_ group user member of.
my problem needs happen automatically our staff forget make change group membership. added condition, users need keep specific group memberships obtained outside of base permissions.
i understand process best achieved using concept known "shadow groups" whereby script automatically adds/removes users set group based on ou membership.
does else have alternative method share?
thanks christoph
this problem plagues companies. when folks leave or change roles, things aren't automatically cleaned up. microsoft has started address issue new feature dac within server 2013 r2. allows definition access objects based on roles.
http://blogs.technet.com/b/windowsserver/archive/2012/05/22/introduction-to-windows-server-2012-dynamic-access-control.aspx
for doing start constant diiligence required workflow procedure.
you @ quest's active roles services.
--
paul bergson
mvp - directory services
mcitp: enterprise administrator
mcts, mct, mcse, mcsa, security+, bs csci
2008, vista, 2003, 2000 (early achiever), nt4
twitter @pbbergs
http://blogs.dirteam.com/blogs/paulbergson
please no e-mails, questions should posted in newsgroup. posting provided "as is" no warranties, , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment