Security vs distribution groups
running windows 2008 r2 , exchange 2010.
we have been cleaning our ad structure , noticed have bunch of security groups, distribution lists , mail enabled security groups.
just wondering why not turn mail enabled security groups? any big reasons why shouldn’t?
thanks.
yes cause doing adds additional sid (the security identifier f security group) members (users) token - space limited , times reached , refered token bloat.
se following thread sample token bloat:
http://social.technet.microsoft.com/forums/ko-kr/winserverds/thread/bf65cc8e-6389-4fa4-993b-2a36f132f704
enfo zipper
christoffer andersson – principal advisor
http://blogs.chrisse.se - directory services blog
Windows Server > Directory Services
Comments
Post a Comment