vjiori Posted June 11, 2011 Posted June 11, 2011 I will be installing several Windows 2008 servers and know how to install Active Directory. My question is because these servers will be in the environment of a state department of corrections and a few users will be inmates who need to be restricted as to what they can access as compared to staff users, I am curious what you might suggest: Should I setup multiple forests? A separate or multiple OUs or just a simply inmate user group and define in that group what inmate accounts can access and NOT include inmate accounts in any domain groups? Thanks, Quote
ICTCity Posted June 11, 2011 Posted June 11, 2011 Hi, Everything depends on who should do what. inmates are only users who has to login into your domain? If yes, put users in a separate OU (or multiple if needed) and group(s). The staff is on another OU / group. Now the point is: what can do a member of the staff to the inmates? What can do a member of staff to another member of staff? Let me know. Quote -------------------------------------------------------- Tu peux aussi crire en franais. Du kannst auch auf Deutsch schreiben. Puoi scrivere anche in italiano. --------------------------------------------------------
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.