Managing AD built-in groups and delegation
Over the course of the past few chapters and discussions, we have learned that several built-in accounts and groups are automatically created during the installation of AD, and a handful of additional built-in groups are installed as well when adding different services to AD, such as Microsoft Exchange. These users and groups that are created are in two specific containers:
- Builtin – objects in this container have a domain local scope
- Users – objects in this container can have either a domain local, global, or universal scope
A great resource that covers more in-depth details on security groups, group scope, and the default security groups can be found at this URL:
Managing AD built-in administrative groups
In the Managing protected users and groups section earlier in this chapter, we identified...