Networking Forums

Networking Forums > Computer Networking > Windows Networking > Logging in to a domain versus using domain "resources"

Reply
Thread Tools Display Modes

Logging in to a domain versus using domain "resources"

 
 
DWalker
Guest
Posts: n/a

 
      07-24-2007, 08:05 PM
I have what ought to be a simple question about domains.

I'm a programmer, but not a network expert by any means.

At our company, all 7 of our users have local logons (on their Windows 2000
and Windows XP computers) that use their names, not "Administrator", and
those user names are also set up in the server's Active Directory with the
same passwords that the users use as their local login passwords.

Most users "log in" to their local computers, and some might log in to the
domain. Question: What is the difference, effectively, between logging in
to the domain, and logging in to the local computer and still using domain
resources like shared folders?

We don't have any roaming profiles, there are no printers or other
"resources" set up in Active Directory (there is only one shared printer,
company-wide), there are no group policies, and everything is very simple
here. There is a one-to-one correspondence between computers and users.

Since the users can all use the shared printer, and the shared folders,
without re-entering their username and password, is there any real
difference between logging in locally and logging in to the domain?

Thanks for any help you can give me in understanding this.

David Walker
 
Reply With Quote
 
 
 
 
Lanwench [MVP - Exchange]
Guest
Posts: n/a

 
      07-24-2007, 08:50 PM
DWalker <(E-Mail Removed)> wrote:
> I have what ought to be a simple question about domains.
>
> I'm a programmer, but not a network expert by any means.
>
> At our company, all 7 of our users have local logons (on their
> Windows 2000 and Windows XP computers) that use their names, not
> "Administrator", and those user names are also set up in the server's
> Active Directory with the same passwords that the users use as their
> local login passwords.


This defeats one of the primary purposes of using Active
Directory....centralized account management.
>
> Most users "log in" to their local computers, and some might log in
> to the domain. Question: What is the difference, effectively,
> between logging in to the domain, and logging in to the local
> computer and still using domain resources like shared folders?


Right now, you're treating your domain like a workgroup. Your users
credentials happen to match the credentials on the server - this lets them
access whatever the domain accounts are granted permission to access. This
works, but isn't ideal. Your users can't change their own passwords, even.
>
> We don't have any roaming profiles, there are no printers or other
> "resources" set up in Active Directory (there is only one shared
> printer, company-wide),


Then why do you have AD?

> there are no group policies,


Yes there are ...you just aren't customizing any of them.

> and everything
> is very simple here. There is a one-to-one correspondence between
> computers and users.
> Since the users can all use the shared printer, and the shared
> folders, without re-entering their username and password, is there
> any real difference between logging in locally and logging in to the
> domain?


Group policies (including folder redirection), login scripts, centralized
account management (a single user ID and password, which the users
themselves would be able to change), for starters.
>
> Thanks for any help you can give me in understanding this.


It would be far better to log into the domain and use that account alone -
disable / delete the local accounts. You can copy the local accounts to the
domain accounts once they've logged in to the domain once on their
workstations; do this by logging in as an administrator & going to control
panel | system | Settings (profile) | copy to....

>
> David Walker




 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Can I configure multiple domain names to dhcpd.conf "optiondomain-name"? tek Linux Networking 1 01-13-2008 05:32 AM
DOMAIN NAME "Fatbøy øf the Underwørld" <uk.fatboy@googlemail.com> Charles Broadband 0 09-14-2006 05:04 PM
Switch 3com and "The system cannot log you on now because the domain "name" is not available." Octavio Alvarez Windows Networking 0 08-03-2005 02:46 AM
Losing "domain\Domain Admins" from the Local Administrators Group Clint Windows Networking 1 07-30-2005 03:22 PM
NIS Setup Help: "Can't bind to server which serves this domain" D. Buck Linux Networking 0 07-08-2004 02:38 AM



1 2 3 4 5 6 7 8 9 10 11