What options does IT have for managing Active Directory groups? What are the pros and cons of each?
There are a couple of ways that organizations currently manage groups in Active Directory. The first option is that IT doesn’t do anything but manage the most obvious and important groups. This approach does not take a lot of IT time so it costs very little. However, an organization will get almost none of the value that accurate group membership can bring. The second option is to have system administrators manually manage group memberships. Groups are generally very accurate, thus increasing productivity and security, but this is an expensive option that takes a lot of time and resources of highly paid and highly trained IT personnel and the user. Finally, IT can use a group management solution, either written internally or bought off the shelf. On the plus side, groups are generally very accurate thus increasing productivity and security, and this approach places very little strain on IT. Be careful, however; if the solution is written in-house, it is rarely scalable or supportable;