How do you do it? Security Groups/Shadow Groups


i'm curious know how other organisations around problem.

  • my user accounts sit in ou structured department (development, finance, it, sales, services)
  • each department has matching security group (gen_development, gen_finance, gen_it, etc.) these security groups have required permissions starting 'base'.
  • users in each department members of gen_ group obtain base set of permissions required department.

when user moves departments, need loose base permissions department , gain base permissions new department. achieved changing gen_ group user member of.

my problem needs happen automatically our staff forget make change group membership. added condition, users need keep specific group memberships obtained outside of base permissions.

i understand process best achieved using concept known "shadow groups" whereby script automatically adds/removes users set group based on ou membership.

does else have alternative method share?


thanks christoph

this problem plagues companies.  when folks leave or change roles, things aren't automatically cleaned up.  microsoft has started address issue new feature dac within server 2013 r2.  allows definition access objects based on roles.
http://blogs.technet.com/b/windowsserver/archive/2012/05/22/introduction-to-windows-server-2012-dynamic-access-control.aspx

for doing start constant diiligence required workflow procedure.

you @ quest's active roles services.


--
paul bergson
mvp - directory services
mcitp: enterprise administrator
mcts, mct, mcse, mcsa, security+, bs csci
2008, vista, 2003, 2000 (early achiever), nt4
twitter @pbbergs
http://blogs.dirteam.com/blogs/paulbergson

please no e-mails, questions should posted in newsgroup. posting provided "as is" no warranties, , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file