What the function of the security group "Domain Users"?

G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

Dear All:

The security group in ADUC called "Domain Users" has everyone and
everything in it,
lots of extra stuff in addition to domain users (people, ie our clients)

I wonder if I can delete things out of there to prune it to just our people
clients safely.

Reason why is, I want to make a distribution list and want only our people
in it,
so this new dist list {DL Everyone} would have the group (Domain Users) as
its member,
after I would clean up Domain Users to only include our people client domain
users.

Would it DISMEMBER the objects I would remove from the
global security list "Domain Users", OR is it just a list I can manipulate
to my needs without affecting domain membship for the object I would remove?

Hope that all made sense

Thank you in advance !


James W. Long.
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

"James W. Long" <JamesLong@wowway.com> wrote in message
news:082dnd18s4GLLJLfRVn-ow@wideopenwest.com...
> Dear All:
>
> The security group in ADUC called "Domain Users" has everyone and
> everything in it,
> lots of extra stuff in addition to domain users (people, ie our clients)
>
> I wonder if I can delete things out of there to prune it to just our
people
> clients safely.

Generally don't mess with Domain Users.

It does NOT contain everyone -- that is Everyone,
a special (should be called Automatic/Dynamic group).

Create a new group for your particular purpose.



--
Herb Martin


"James W. Long" <JamesLong@wowway.com> wrote in message
news:082dnd18s4GLLJLfRVn-ow@wideopenwest.com...
> Dear All:
>
> The security group in ADUC called "Domain Users" has everyone and
> everything in it,
> lots of extra stuff in addition to domain users (people, ie our clients)
>
> I wonder if I can delete things out of there to prune it to just our
people
> clients safely.
>
> Reason why is, I want to make a distribution list and want only our people
> in it,
> so this new dist list {DL Everyone} would have the group (Domain Users) as
> its member,
> after I would clean up Domain Users to only include our people client
domain
> users.
>
> Would it DISMEMBER the objects I would remove from the
> global security list "Domain Users", OR is it just a list I can manipulate
> to my needs without affecting domain membship for the object I would
remove?
>
> Hope that all made sense
>
> Thank you in advance !
>
>
> James W. Long.
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

How dissapointing. I had hoped to save myself the work of adding
each and every user to a new Distribution list to email "all"
Hm wonder if I could copy it?

James W. Long

"Herb Martin" <news@LearnQuick.com> wrote in message
news:O%23wSHChEFHA.2232@TK2MSFTNGP14.phx.gbl...
> "James W. Long" <JamesLong@wowway.com> wrote in message
> news:082dnd18s4GLLJLfRVn-ow@wideopenwest.com...
> > Dear All:
> >
> > The security group in ADUC called "Domain Users" has everyone and
> > everything in it,
> > lots of extra stuff in addition to domain users (people, ie our
clients)
> >
> > I wonder if I can delete things out of there to prune it to just our
> people
> > clients safely.
>
> Generally don't mess with Domain Users.
>
> It does NOT contain everyone -- that is Everyone,
> a special (should be called Automatic/Dynamic group).
>
> Create a new group for your particular purpose.
>
>
>
> --
> Herb Martin
>
>
> "James W. Long" <JamesLong@wowway.com> wrote in message
> news:082dnd18s4GLLJLfRVn-ow@wideopenwest.com...
> > Dear All:
> >
> > The security group in ADUC called "Domain Users" has everyone and
> > everything in it,
> > lots of extra stuff in addition to domain users (people, ie our
clients)
> >
> > I wonder if I can delete things out of there to prune it to just our
> people
> > clients safely.
> >
> > Reason why is, I want to make a distribution list and want only our
people
> > in it,
> > so this new dist list {DL Everyone} would have the group (Domain Users)
as
> > its member,
> > after I would clean up Domain Users to only include our people client
> domain
> > users.
> >
> > Would it DISMEMBER the objects I would remove from the
> > global security list "Domain Users", OR is it just a list I can
manipulate
> > to my needs without affecting domain membship for the object I would
> remove?
> >
> > Hope that all made sense
> >
> > Thank you in advance !
> >
> >
> > James W. Long.
> >
> >
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

"James W. Long" <JamesLong@wowway.com> wrote in message
news:yuqdnWtiPbVoTZLfRVn-jw@wideopenwest.com...
>
> How dissapointing. I had hoped to save myself the work of adding
> each and every user to a new Distribution list to email "all"
> Hm wonder if I could copy it?
>

You cannot EXACTLY copy it but there was code
(around) here the other day for dumping the contents
of a group which could also be used to add them back
in (with a treak or two) into a new group.

This may not save you much time on THIS OCCASION,
but learning to do it and using it in the future will quickly
become a big time saver if you have much management
to do....

--
Herb Martin


"James W. Long" <JamesLong@wowway.com> wrote in message
news:yuqdnWtiPbVoTZLfRVn-jw@wideopenwest.com...
>
> How dissapointing. I had hoped to save myself the work of adding
> each and every user to a new Distribution list to email "all"
> Hm wonder if I could copy it?
>
> James W. Long
>
> "Herb Martin" <news@LearnQuick.com> wrote in message
> news:O%23wSHChEFHA.2232@TK2MSFTNGP14.phx.gbl...
> > "James W. Long" <JamesLong@wowway.com> wrote in message
> > news:082dnd18s4GLLJLfRVn-ow@wideopenwest.com...
> > > Dear All:
> > >
> > > The security group in ADUC called "Domain Users" has everyone and
> > > everything in it,
> > > lots of extra stuff in addition to domain users (people, ie our
> clients)
> > >
> > > I wonder if I can delete things out of there to prune it to just our
> > people
> > > clients safely.
> >
> > Generally don't mess with Domain Users.
> >
> > It does NOT contain everyone -- that is Everyone,
> > a special (should be called Automatic/Dynamic group).
> >
> > Create a new group for your particular purpose.
> >
> >
> >
> > --
> > Herb Martin
> >
> >
> > "James W. Long" <JamesLong@wowway.com> wrote in message
> > news:082dnd18s4GLLJLfRVn-ow@wideopenwest.com...
> > > Dear All:
> > >
> > > The security group in ADUC called "Domain Users" has everyone and
> > > everything in it,
> > > lots of extra stuff in addition to domain users (people, ie our
> clients)
> > >
> > > I wonder if I can delete things out of there to prune it to just our
> > people
> > > clients safely.
> > >
> > > Reason why is, I want to make a distribution list and want only our
> people
> > > in it,
> > > so this new dist list {DL Everyone} would have the group (Domain
Users)
> as
> > > its member,
> > > after I would clean up Domain Users to only include our people client
> > domain
> > > users.
> > >
> > > Would it DISMEMBER the objects I would remove from the
> > > global security list "Domain Users", OR is it just a list I can
> manipulate
> > > to my needs without affecting domain membship for the object I would
> > remove?
> > >
> > > Hope that all made sense
> > >
> > > Thank you in advance !
> > >
> > >
> > > James W. Long.
> > >
> > >
> >
> >
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

In addition I would wonder how well Exchange would handle enumerating the
membership of that group for expansion because the members aren't actually
listed in the member attribute if that is their primary group.

joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net


Herb Martin wrote:
> "James W. Long" <JamesLong@wowway.com> wrote in message
> news:082dnd18s4GLLJLfRVn-ow@wideopenwest.com...
>
>>Dear All:
>>
>> The security group in ADUC called "Domain Users" has everyone and
>>everything in it,
>> lots of extra stuff in addition to domain users (people, ie our clients)
>>
>> I wonder if I can delete things out of there to prune it to just our
>
> people
>
>>clients safely.
>
>
> Generally don't mess with Domain Users.
>
> It does NOT contain everyone -- that is Everyone,
> a special (should be called Automatic/Dynamic group).
>
> Create a new group for your particular purpose.
>
>
>