Directory administration.
WHAT TO ESTABLISH
A naming convention for accounts and groups An organisational unit structure A group strategy
WHAT STRUCTURE TO USE FOR ORGANISATIONAL UNITS
Something reflecting how policy and administration are applied.
WHAT NOT TO USE
The organisation chart, which changes.
WHAT GROUP TYPES EXIST
Security groups, for permissions Distribution groups, for mail
WHAT SCOPES EXIST
Domain local, global and universal.
WHAT THE CONVENTIONAL APPROACH IS
Accounts into global groups, global groups into domain local groups, permissions on domain local groups.
WHY THAT STRUCTURE
It scales and keeps permission assignment manageable.
WHAT TO NEVER DO
Assign permissions to individual accounts.
WHY
They accumulate and are never removed.
WHAT TO DOCUMENT
What each group is for, in its description field.
WHAT TO REVIEW
Accounts that have not signed in for a long period Groups with no members Accounts with passwords set never to expire
WHAT TO DISABLE PROMPTLY
Accounts of people who have left.
WHY NOT DELETE IMMEDIATELY
Their access may need to be transferred first.