  • Understand the difference between authorization and authentication.

  • Understand the relationship between standard and special permissions.

  • Know how effective permissions are calculated.

  • Be able to compare the various types of groups, and to diagram how different types of groups can be nested.

  • Be able to list the built-in and special groups.

  • Be able to create group naming strategies to suit various types of environments.

  • Be able to troubleshoot authorization problems.

access control entry An entry in an object's access control list that grants permissions to a user or group.

access control list A collection of access control entries that collectively defines the access that all users and groups have to the object.

authorization The process of determining whether a user, after having been validated, really should have access to do what he or she has requested.

least privilege A fundamental security principle wherein the administrator makes an effort to grant users only the minimal permissions they need to do their job.

special groups Groups created by Windows Server 2003 whose membership is dynamic and determined by the way a user interacts with the system.

