Jump to content

Mail-enabled universal security group vs AD security group


Recommended Posts

Posted

Hi

 

I have a questions regarding file permissions of folders and linking this with a distribution group using Exchange 2007. Please accept my apoligises if I have put this thread into the wrong section but I feel this may be the best section.

 

In our school we have a flat Windows 2008 AD domain with 2 DCs on a single forest and a 2008 File server. I am guessing most schools have this problem where the staff shared folder over time increases and becomes a mess. I am currently looking at sorting out this share where multiple users and groups currently save, delete and create documents on.

 

I want to change this to allow only certain groups to be able to save work on there. What would also be useful is if that same group could also be used as a distribution group for email. We use exchange 2007 on the network as well.

 

I wanted to ask what advantages and disadvantages are there for using 'mail enabled universal security groups' in Exchange 2007 which I think will allow me to use a group as a distribution list in Outlook as well as a AD security group to provide permissions for folders.

 

Would I be better of creating 2 groups with same name, one which will be a mail enabled distribution group for use with exchange and then create a normal security group in AD which would be used to lock down persmissions on files and folders.

 

The first option sounds great but I am thinking what effect would this have if we ever decided to remove exchange or upgrade exchange, what effect would this have with the folder permissions? if I used mail enabled universal security groups.

 

If anyone could advise that would be great. The first option would be better as it will save me creating duplicate groups and manually adding in members and it also means 1 group to manage for each department and team.

 

Thanks

Posted

Hi

 

This is exactly what they are used for. Use one mail-enabled security group for ACL and mail. If you decomm Exchange only those attributes will be moved the group, the ACL will still be applied.

 

Sukh

  • Thanks 1
Posted
Hi

 

This is exactly what they are used for. Use one mail-enabled security group for ACL and mail. If you decomm Exchange only those attributes will be moved the group, the ACL will still be applied.

 

Sukh

 

Thats great, thanks for that Sukh. Am I right in saying that if I am creating mail enabled security groups I need to create these in Exchange MMC and not AD users and computers?

I just tried to create a test group in AD groups and it didnt appear in exchange distribution group even though I set the AD group to universal security and added in an email address.

Posted
Mail enabled security groups work fine as long as you are sure that you want all members of the security group to be on the distribution list. We have hit problems where additional members of staff (cover teachers, supply staff, students etc) require access to some of the restricted folders but do not want to be on the departmental distribution list. This means they have to be added - and removed - manually on each folder instead of just being made members of the security group

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...