EXERCISE 1.02.E XERCISE 1.02C REATING G ROUPS WITH A CTIVE D IRECTORYU...

271_70-292_01.qxd 8/21/03 12:40 PM Page 3232 Chapter 1 • Managing Users, Computers, and Groups

discussion of groups with a brief examination of how user rights and permissions can be

assigned to them.

Assigning user rights to a group can be done in several places, each at a different level

within the overall Active Directory domain hierarchy.The following list contains some

locations and ways that user rights can be assigned to a group:

Default Domain Controller Security Settings Console Located in the

Administrative Tools folder, this console can be used to configure user rights

assignments for all domain controllers. Domain controllers are located in the

Domain Controllers container in Active Directory Users and Computers.

Default Domain Security Settings Console Located in the Administrative

Tools folder, this console can be used to configure user rights that will be applied

to the domain as a whole.

Local Security Policy Console Located in the Administrative Tools folder, this

console can be used to configure user rights that will be applied only to the local

computer.

Group Policy Objects (GPOs) GPOs can be applied at various levels in

Active Directory, such as the domain level or to a specific Organizational Unit.

Within each GPO, user rights can be assigned that will affect all objects the GPO

has been applied to.

Security Templates Security Templates can be used to quickly and uniformly

apply security settings to all objects they have been applied to. Security Templates

can be applied directly to a local computer or imported into a GPO for applica-

tion to all objects the GPO is applied to. Security Templates are discussed in more

detail in Chapter 7.