05.03.2013 Views

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

F07us10<br />

Assign permissions<br />

once for a group<br />

Group<br />

permissions<br />

Figure 7-10 Groups simplify administration.<br />

Guidelines for Using Local Groups<br />

- instead of -<br />

Resources<br />

Groups are collections of user accounts.<br />

Members receive permissions given to groups.<br />

Users can be members of multiple groups.<br />

Groups can be members of other groups.<br />

7-37<br />

A local group is a collection of user accounts on a computer. Use local groups to assign<br />

permissions to resources residing on the computer on which the local group is created.<br />

Windows XP Professional creates local groups in the local security database.<br />

Guidelines for using local groups include the following:<br />

Lesson 5 Implementing Groups<br />

Assign permissions for<br />

each user account<br />

permissions<br />

permissions<br />

permissions<br />

■ Before creating a new group, determine whether a built-in group (or other existing<br />

group) fits your needs. For example, if all users need access to a resource, use<br />

the built-in Users group.<br />

■ Use local groups on computers that do not belong to a domain. You can use local<br />

groups only on the computer on which you create them. Although local groups<br />

are available on member servers and domain computers running Windows 2000<br />

Server or later, do not use local groups on computers that are part of a domain.<br />

Using local groups on domain computers prevents you from centralizing group<br />

administration. Local groups do not appear in the Active Directory service, and<br />

you must administer them separately for each computer.<br />

■ You can assign permissions to local groups to access only the resources on the<br />

computer on which you create the local groups.<br />

Note You cannot create local groups on domain controllers because domain controllers<br />

cannot have a security database that is independent of the database in Active Directory.<br />

User<br />

User<br />

User

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!