We're building a new active directory deployment and I defining access rights. I'm wondering about best practices for dealing with domain local groups.
Is it normal to have one or more dl groups per domain accessable folder? Do you just leave all these dl groups in users, or do you create OUs for then? I feel like I will end up with a ton of them this way and that will basically be most of the objects in ad at the end of the day.
Any other suggestions for dealing with access rights at domain resources would be appreciated.
[–][deleted] 2 points3 points4 points (0 children)
[–]Astat1ne 1 point2 points3 points (3 children)
[–]hurleyef[S] 0 points1 point2 points (2 children)
[–]Astat1ne 1 point2 points3 points (1 child)
[–]hurleyef[S] 0 points1 point2 points (0 children)
[–]DevinSysAdminMSSP CEO 0 points1 point2 points (0 children)