Domain Trust Security Groups
Can be a strong supplement to your well rounded security policy.
Domain trust security groups. When creating a new security group the group scope can sometimes be confusing. Do i pick domain local global or universal. You can use these predefined groups to help control access to shared resources and to delegate specific domain wide administrative roles. Domain admin is a global group and global group can t have member from the other domain.
The purpose of establishing a trust is to allow users from one domain to access resources like the local administrators group on a server to be nested in groups or to otherwise be used as security principals in another domain e g. Here is the powershell script i made and ran from the trusted domain side to quickly add the trusted groups to the domain local groups of the trusting domain. Maintaining a more secure environment. The desired functionality is obtained but not exceeded before using live groups.
Before deploying a domain trust. Default groups such as the domain admins group are security groups that are created automatically when you create an active directory domain. The trusting domain was windows 2003 and we did not have access to any ad powershell module in the trusting domain so the only way to do this is using dsmod. Protected accounts and groups in active directory.
Privileged accounts and groups in active directory. Security groups are used to control access to resources. For ad object acls. Add the user accounts to global groups global groups to universal group universal groups to domain local groups domain local groups to the group you want to assign the permission.
As a system administrator of a domain there will obviously be times where you will need to create new security groups for your environment. You need to use agudlp accounts global universal domain local permissions method to add user in groups. In a single domain the scope of groups will have no effect on performance. Securing domain controllers against attack.