Problem:
1. User control, we usually use the resource sharing time, can be in accordance with the group or individual users to control the rights, then, when a file of the visitors can only be the head of the department, how to do? We can create a group for a department head. What if the visitor to a file can only be a departmental assistant? We create a group for the assistant. ...... This way down, there will be many groups, individual users belong to many groups, to the management of great trouble.
2. Resource control, the shared folder on the server is only allowed to be accessed by the supervisor of a department, how to set?
3. Device control, the user with a private computer to the company, joined the domain can access the company's files?
Workaround: DAC
1. Configure the DC environment to support the DAC.
Open Group Policy Management Editor, computer Configuration, policies, administrative Templates: ...-syst The right panel, KDC-------"KDC support for claims, compound authentication and Kerberos armoring" Enabled-OK
win2012 Configuring the DAC