发明名称 Group types for administration of networks
摘要 An improved system and method for network management is presented which facilitates better administration with a more intuitive reflection of the organizational structure with integrated security concerns by introducing novel strategies for grouping users of a network. In particular, a new group, the Universal Group, is introduced to facilitate nested groups with members in more than one Domain. Members of a universal group may be allowed access to resources across Domain boundaries, where Domains reflect a security boundary in the Network. In addition, the nesting of groups, e.g., within Universal Groups, is enabled, subject to some restrictions, in order to reduce the overhead associated with discovering the groups to which a user belongs. Furthermore, allowing a group to include members without security clearance, but restricting the groups listed on an access token corresponding to a user to groups to which the user has security clearence/authorizarion allows flexible management of groups having similar memberships but different security attributes.
申请公布号 US7103784(B1) 申请公布日期 2006.09.05
申请号 US20000565083 申请日期 2000.05.05
申请人 MICROSOFT CORPORATION 发明人 BROWN MARK R.;SATAGOPAN MURLI;STAUBE DAVE DETLEF
分类号 G06F12/00 主分类号 G06F12/00
代理机构 代理人
主权项
地址