How it works...
In multi-domain and multi-forest environments, it is a common practice to use universal groups to traverse Active Directory trusts. This is also why, in Microsoft Exchange Server, it is recommended you create this type of groups for distribution lists, instead of domain local groups or global groups.
However, for every logon, a global catalog server is required to enumerate the universal groups the account is a member of. In multi-domain and multi-forest environments, global catalog servers require more replication, and, therefore, replication bandwidth. Often, it is far from ideal to place global catalogs in poorly-connected Active Directory sites.
To accommodate the scenario of a non-global catalog in an Active Directory ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access