Jump to content

Users... Authenticated Users... Domain Users... Which are they?


Recommended Posts

Posted

Hi All,

 

Over the half-term I moved 99% of staff shared areas, mapped drives, staff data etc. That is in preparation for nuking the old 2008 server into a 2012R2.

 

Looking over permissions and security became a bit complicated due to me wanting to only use GPP to map drives, but different people wanting different parts of the shared drives. I wanted to get away from log-in scripts, manual mapping and such, but just using preferences it seem hard to give one person a drive map and not the other in the same GPO obviously (meaning individuals having their own GPO and I don't want to start that - as I'm trying to simplify things, not complicate them)...

 

An example of this is say, the admin drive - within it there are folders that the admin staff should not have access to and so I have had to manually stop inheritance and only given permission to those who require it.

 

Or another is say, the SLT team, one of those is also part of the PCT and needs the PCT drive mapped, the other members of SLT do not need this drive mapped - but using preferences I can only map that drive for the whole of the SLT in that GPO.

 

How does everyone else get around this?

 

Also looking through security permissions, I have found and deleted a lot of old security groups but I am also stuck on the best practise for which groups need to be included, some staff are members of:

 

Users

Domain Users

Authenticated User

 

I presume these are built-in groups, but what is the minimum I can take this down to and still let users log-on to the domain?

 

Kol.

Posted (edited)

We provide a single group drive and use Access Based Enurmeration to limit what the user can see. The department groups folders only have permissions for the department group (and additional users if required). That way everyone gets a group drive but only their department folders show up.

 

So if I was in IT & Tech I would see

Group Drive>

IT

Tech

 

Others would see

Group Drive>

Library etc.

 

So in your example you could set domain users access to the admin drive but set it to "this folder only" and then add specific groups to the sub folders. That way if you create new folders you don't have to worry about disable inheritance.

 

Edit: You can also use GPP to map drives and select the Item level targeting so it only applies to specific groups to allow you to use a single GPO

Edited by penfold
  • Thanks 1
Posted

Thanks for the info... Always learning!

 

Any ideas on what security groups/inbuilt groups users should belong to as a minimum?

 

Kol.

Posted

I have done this. When creating the GPO if you click on advanced (not %100 sure what its called) you can use GPO targeting to target a security group.

 

So if 1 teacher needs access to something extra, create a group, add this teacher to this group and then in the GPO settings select to target that teachers group. only someone in that group will get that gpo.

 

Sorry not near a server atm so if you need more info let me know.

Posted

Cool, thanks - Guess I have much more reading/testing to do on those options.

 

On my other question though (that might have got lost in the tl;dr)...

 

I am interested in what groups other techs put staff in?

 

Also what is the point of them being a member of a particular group, unless it's security groups for share access.

 

For instance, some of my staff are in all of the following groups:

 

Users

Authenticated Users

Domain Users

 

There are no shares that I can find that are set-up to specifically allow access to these groups of users, so my question is do they need to be a member of these groups?

 

Kol.

Posted

These are default domain groups. Creating any new user will be "added" to these

 

There is no way to remove a user from "Users" or "Authenticated Users". You can remove them from Domain users but I would honestly advise against any such action as you'll be opening yourself up to a huge mess with permissioning down the line

Posted

 

I am interested in what groups other techs put staff in?

 

Also what is the point of them being a member of a particular group, unless it's security groups for share access.

 

 

The types of groups really depends on how granular you want to be. You could go SLT, ALT, Maths, English, Finance, etc. but again it depends on what you are going to do with those groups.

 

Don't just think of groups being used for 'Shares' either as you can use them to filter all sorts such as GPO's via the 'Security Filtering' or ITL 'Item Level Targetting' on certain GPPs.

 

For instance you mention mapping a drive via GPP and having to use all of SLT but you could do an ITL saying only map for each user if they are a member of the "PCT" group. You could even go as far as to say they are a member of group A but NOT a member of group B.

 

Access Based Enumeration as Penfold says is also a good option and looks a lot better if you can get it all set up initially.

Posted
These are default domain groups. Creating any new user will be "added" to these

 

There is no way to remove a user from "Users" or "Authenticated Users". You can remove them from Domain users but I would honestly advise against any such action as you'll be opening yourself up to a huge mess with permissioning down the line

 

Ah... Ok... Well I appear to have done the exact opposite and removed them from 'Users' AND 'Authenticated Users', but left them in 'Domain Users'... :doh:

 

How long do I have to either fix it or quit my job do you think? :confused:

 

Kol.

Posted
Ah... Ok... Well I appear to have done the exact opposite and removed them from 'Users' AND 'Authenticated Users', but left them in 'Domain Users'... :doh:

 

How long do I have to either fix it or quit my job do you think? :confused:

 

Kol.

 

Do you mean you've removed those permissions from a share? as that's perfectly fine. There is a difference from removing the share permission as to removing the user from the group. :o

Posted

I am interested in what groups other techs put staff in?

I have loads that correspond to various groups of staff that need something a bit different.

Eg every subject has a group, admin staff, premises staff, teachers, TAs, techs, staff with permission to view CCTV, VPN users, Inventry Managers etc etc

 

In terms of drive maps I have one GPO that uses GPPs and Item Level Targetting (this is really your friend) that sorts it all out at login. It does a fair bit of work at each login but doesn't affect the login times very much at all.

Posted

Ah no, I removed the user groups in their AD properties in the 'Member Of' tab... Anyway, I did it a couple of days ago and nobody has complained as of yet...

 

However, I think it is becoming clear (as mud) and that I need a bit of server 101!

 

They are still a member of 'Users' as that is the AD default container and 'Domain Users' is a 'Global Security Group' within that.

 

Can't find 'Authenticated User' anymore - Is that a legacy thing?

 

Kol.

Posted
Ah no, I removed the user groups in their AD properties in the 'Member Of' tab... Anyway, I did it a couple of days ago and nobody has complained as of yet...

 

However, I think it is becoming clear (as mud) and that I need a bit of server 101!

 

They are still a member of 'Users' as that is the AD default container and 'Domain Users' is a 'Global Security Group' within that.

 

Can't find 'Authenticated User' anymore - Is that a legacy thing?

 

Kol.

 

It's a non changeable "group" anything that authenticates in your domain will be part of this....even you devices are part of this :-)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...