Jun 20 2017 02:04 AM
Recently we experience issues with SharePoint security set using AD groups:
Members of these groups are intermittently getting access denied. A few hours later they are able to access the resource (eg site) without error.
The strange thing is that if the AD group is encapsulated in a SharePoint security group, the issue is not present. Members of the AD group when encapsulated are not getting this erroneous behaviour.
Jun 20 2017 02:20 AM
@Bart Vermeersch wrote:
[..]
The strange thing is that if the AD group is encapsulated in a SharePoint security group, the issue is not present. Members of the AD group when encapsulated are not getting this erroneous behaviour.
Would need more clarification on this last paragraph of yours, specifically what do you mean by "encapsulation"?
I am not sure about the error, however for the other part - from what I can understand, this is actually a best practice. For any given site (or collection), there are by default at least three SP Groups - Site Visitor, Site Members, and Site Owners. You would typically add AD Security Groups to one of these default groups and are good to go. Should you need any specific access control, you create an SP Group and add the relevant AD Security Group there.
Jun 20 2017 09:31 AM
Jun 20 2017 01:35 PM
From the Search perspective you to take a hit when individual permissions are used as opposed to AD. When you add individuals to a SP group a full crawl will be launched at the next pass of content in order to calculate the ACLs for each individual. So - if you add 100 individuals you will have 100 ACLs calculated for every piece of content. If you have 1 AD group with 100 users you only have 1% of the hit in the crawl.
Precisely as @Trevor Seward stated the general guidance from Technet is this :
Considering the previous advantages and disadvantages, here are the recommendations:
Jun 21 2017 03:01 AM
To go back to my initial issue ;)
We found there are two seperate issues, the one we figured out properly goes as follows:
Target audiences set on navigation menu (I know it's not best practice from perfomance point of view).
If the target audience contains a (synced) AD group, it sometimes fails (members of the AD group don't see the menu item).
If a SharePoint groups is created with the AD group as only member, and this SharePoint group is put in the target audience, we don't experience any issues.
So we are creating SharePoint groups (for every AD groups) and use these for target audience.
Jun 21 2017 10:33 AM
Jan 21 2018 06:12 PM
Hi Trevor
we have a issue when we add 'AD Security group' added to SharePoint (2016) . groups. the users able to login to the site, but they can't see any search results till we added them as individual. we got 4000+ users who need readonly access to the Intranet home pages. I have added the AD domain security group to the SharePoint groups.
let us know where to check to resolve the issue. The ULS logs only says
Microsoft.Office.Server.Search.Query.Ims.ImsQueryInternal : Number of tables in Result: 3, Relevant Results: 0 (Total: 0, Total including duplicates: 0),
how a member of AD security group can see the search results. we are using Cloud Search service application.
Jan 25 2021 02:43 AM
@Trevor Seward interesting discussion that reveals a lot. Where is this knowledge documented: "Compilation only occurs on Sunday in the early AM hours" for SharePoint Online? Is that still the case?