When to Go to Native Mode

Several features point you to going to Native Mode. With Native Mode, you have more group types and group management with nested groups.

The availability and functions of groups are described in Table 22.1. The new group types are domain local groups and universal groups. Domain local groups are similar to local groups except that they are domain wide. Domain local groups enable access to resources in the domain. This is just like local groups enabling access to machine- specific resources. Universal groups have Forest-wide scope. Universal groups can give access to resources in the any domain in the Forest and to domains in other Forests, as long as the proper trust relationship exists.

Table 22.1. Group Type Availability and Function
Group Type Mode Available Function
Local GroupMixed and NativeAccess to machine-wide resources.
Domain Local GroupNative onlyAccess to domain-wide resources and can be used on any machine in the domain. They are limited to their local domain.
Global GroupMixed and NativeSimilar to Windows NT global groups. Domain-wide membership scope and can be given permissions in other domains.
Universal GroupsNative onlyMembership and permissions Forest wide.

Native Mode removes the need for BDC replication traffic, and the PDC is eliminated. The SAM size limitation is lifted as well.

Staying in mixed-mode does not affect client access. There are a few reasons to stay in mixed-mode. They include not having adequate hardware to run Active Directory, wanting a fallback position, and not being able to upgrade BDCs because of applications that will not upgrade.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.147.45.212