You've been called in as a consultant to review security group design proposals for a technology firm. Several sources have submitted the proposals, and the firm fears that some of the proposals are technically incorrect. The proposals all pertain to providing access to a shared folder named Technologies. The folder is stored on a member server named Development that's a member server in the east.technology.tld domain. The shared folder must be accessible to user accounts in both the west.technology.tld and technology.tld domains, as shown in Figure 5.6.
Figure 5.6 The technology.tld domain structure
Only members of the marketing, sales, and management teams must have access to the technologies share. No other users should have access.
Due to some legacy applications running on Windows NT 4.0 BDCs, all domains in the Windows 2000 forest are currently running in mixed mode.
Proposal 1
To provide access to the \\Development\Technologies share, you must define the following groups:
- Marketing. A global group defined in each domain that will contain marketing users for that domain.
- Sales. A global group defined in each domain that will contain Sales department users for that domain.
- Management. A global group defined in each domain that will contain management staff for that domain.
- TechUsers. A global group defined in each domain that will contain the Marketing, Sales, and Management global groups.
- TechAccess. A domain local group defined in the east.technologies.tld domain. This group will contain the TechUsers groups from each of the three domains.
Proposal 2
To provide access to the \\Development\Technologies share, you must define the following groups:
- Marketing. A global group defined in each domain that will contain marketing users for that domain.
- Sales. A global group defined in each domain that will contain Sales department users for that domain.
- Management. A global group defined in each domain that will contain management staff for that domain.
- TechAccess. A computer local group defined in the east.technologies.tld domain. This group will contain the Marketing, Sales, and Management global groups from each of the three domains.
Proposal 3
To provide access to the \\Development\Technologies share, you must define the following groups:
- Marketing. A global group defined in each domain that will contain marketing users for that domain.
- Sales. A global group defined in each domain that will contain Sales department users for that domain.
- Management. A global group defined in each domain that will contain management staff for that domain.
- TechUsers. A universal group defined in the east.technologies.tld domain that will contain the Marketing, Sales, and Management global groups.
- TechAccess. A computer local group defined in the east.technologies.tld domain. This group will contain the TechUsers groups from each of the three domains.
Proposal 4
To provide access to the \\Development\Technologies share, you must define the following groups:
- Marketing. A global group defined in each domain that will contain marketing users for that domain.
- Sales. A global group defined in each domain that will contain Sales department users for that domain.
- Management. A global group defined in each domain that will contain management staff for that domain.
- TechAccess. A domain local group defined in the east.technologies.tld domain. This group will contain the Marketing, Sales, and Management global groups from each of the three domains.
Questions
Answer the following questions about this situation. Answers can be found in the appendix.
- Will the first proposal work in technology.tld's environment? If your answer is no, what's wrong with the proposal?
- Will the second proposal work in technology.tld's environment? If your answer is no, what's wrong with the proposal?
- Will the third proposal work in technology.tld's environment? If your answer is no, what's wrong with the proposal?
- Will the fourth proposal work in technology.tld's environment? If your answer is no, what's wrong with the proposal?
Answers