Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

We have a finance software package that will be sitting on a 2008 R2 box connected to our Active Directory.

 

It uses two Windows groups to assign appropriate security rights (The database is SQL so the groups are effectively added as SQL users to assign the rights as required).

 

Now the members of the groups are pulled from Active Directory as it is just the Finance staff normal login accounts, but is it best practice to place the actual groups in the Active Directory or just have them on the Finance server since that is the only software that will be using the groups?

 

Hope this makes some form of sense!

Posted

I think he answer is, it depends.

 

Which is more likely in your environment?

a) the service and data need to be migrated to a new server

b) the server, service and data need to be migrated to a new domain

 

if a) then Universal Groups from AD

if b) the put the Universal groups from AD into groups local to the SQL server SAM.

 

Possibly.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...