ActiveDirectoryAllows administrators to create group accounts, allowing administrators to manage system security more effectively. The system controls the access to objects in Active Directory based on the user's group membership identity. The following describes how to create and add a group in the Active Directory of ActiveDirectory.Group members.
In ActiveDirectory, users with the same attributes can be put into the same group, which greatly improves the efficiency of user management. For example, if you want to grant the same permission to a user in a group, you only need to grant the permission to the group, without having to grant permissions to each user separately.
To create a group or add a group member in ActiveDirectory, follow these steps:
Step 2: Activate the domain controller as a system administrator. Open the "ActiveDirectory user and computer" window and select a domain name such as msserver.com.cn in the left pane ). Then select "operation"> "new"> "group" menu command, as shown in 1.
Figure 1 select "group" menu command
Step 2: Open the "new object-group" dialog box, and enter the name of the created group, such as JinshouzhiUsers, in the "group name" edit box ). Then, select "Global" single region in the "Group Scope" area, and select "Security Group" single region in the "Group type" area. Click OK, as shown in figure 2.
Figure 2 "new object-group" dialog box
TIPS:A group can be divided into two types: "Security Group" and "Distribution Group". For each type of group, different scopes can be assigned, that is, "Local Region", "Global", and "General ".
Step 2: select the Users container in the "ActiveDirectory Users and computers" window, and double-click the group name, such as JinshouzhiUsers, in the right pane. The "JinshouzhiUsers attributes" dialog box is displayed. Switch to the "members" tab, and click "add"> "advanced"> "Search now. Select multiple user accounts in the user list, and click OK to add group members, as shown in figure 3.
Figure 3 "members" tab
TIPS:You can also right-click a user account in the "ActiveDirectory users and computers" window and select the "add to group" command to add group members.
Step 2: switch to the "affiliated" tab and click "add"> "advanced"> "Search now. In the user list, select the upper-level group, such as Administrators and System Administrator group. Click OK> OK, as shown in 3.
Figure 3 "affiliated" tab
Step 2: switch to the "manager" tab and click "change"> "advanced"> "Search now. Select an administrator account for the Group in the user list, and click "OK"> "OK" to return to the "manager" tab. Select the "administrator can update member list" check box and click "OK" to close the "JinshouzhiUsers attributes" dialog box, as shown in figure 4.
Figure 4 "manager" tab
Summary:
In ActiveDirectory, you can create a group and add group members to put users with the same attributes into the same group, which greatly improves the efficiency of user management. It is hoped that the method of creating a group and adding group members in ActiveDirectory described in this article will be helpful to readers. More information about ActiveDirectory remains to be explored and learned by readers.
Edit recommendations]