I’m implementing a tool which secures certain shared resources within AD forest (mostly file shares). By some criteria a list of users from different domains is generated, those users are added to a universal group (because J’ai besoin de to gather users from different domains in a single group) and then that universal group is added to a shared resource ACL.
The forest has roughly 10 000 users, Je pense my universal groups will end up having up to 2000 users in each. And there might be up to several thousand those groups.
Everything looks good and works in test environment.
Le problème est that tVoici an MS article on groups bonne pratiques: http://technet.microsoft.com/en-us/library/cc787646(v=ws.10).aspx
Almost le même is written here:
http://ss64.com/nt/syntax-groups.html
In “Bonne pratiques for controlling access to shared resources across domains” section
it reads that I should create domain local groups and nest global/universal groups in it.
I understand that tVoici an administrative benefit in it, easier management, visibility, etc
But I’m doing everything automated and my tool will watch for the right security by itself.
Some our IT consultants try to persuade me that not following that bonne pratique may also result in poor performance.
So basically the question is: Can there be a performance (it means time required to logon, to secure a directory, etc) impact if I add universal groups directly on the shared resource instead of nesting universal group in a domain local group?
Merci in advance.
Mise à jour :
TVoici also one restriction regarding nesting groups. (http://support.microsoft.com/kb/328889)
TVoici a limit of 1015 user’s groups. So In case of nesting universal groups into domain local groups I get ~ 500 limit, which seems like a painful restriction.
UPDATE2:
Regarding my forest topology. J’ai 6 domains, grouped into 2 trees. (Tree consists of a root domain, and two child domains)
Source : [Server Fault](Accessing resources across domains: Active Directory | Microsoft Learn](Accessing resources across domains: Active Directory | Microsoft Learn)