Assigning different LUs to common groups in SNA Server (150454)



The information in this article applies to:

  • Microsoft SNA Server 2.0, when used with:
    • the operating system: Microsoft Windows NT
  • Microsoft SNA Server 2.1, when used with:
    • the operating system: Microsoft Windows NT
  • Microsoft SNA Server 2.11, when used with:
    • the operating system: Microsoft Windows NT
  • Microsoft SNA Server 3.0, when used with:
    • the operating system: Microsoft Windows NT
  • Microsoft SNA Server 4.0, when used with:
    • the operating system: Microsoft Windows NT
  • Microsoft SNA Server 4.0 SP1
  • Microsoft SNA Server 4.0 SP2
  • Microsoft SNA Server 4.0 SP3
  • Microsoft SNA Server 4.0 SP4
  • Microsoft Host Integration Server 2000
  • Microsoft Host Integration Server 2000 SP1

This article was previously published under Q150454

SUMMARY

It is not recommended that you assign different LUs to user groups that have members in common because the results cannot be predicted.

MORE INFORMATION

According to the SNA Server version 3.0 "Administration Guide," Chapter 3: If a user is assigned LUs through one or more accounts, such as group accounts and the user's individual account, the LUs do not accumulate. Instead, one account determines the access for that user. The account that determines this access is the account found first in the following search order:
  1. User accounts (highest priority)
  2. Domain groups
  3. Local groups
  4. Well-known groups such as Everyone (lowest priority)
However, it does not explain clearly what will happen if two groups are at the same level (2 local groups).

SNA Server will use the LUs assigned to whichever group is returned first from Microsoft Windows NT, and there is no way to predict the order in which the groups will be returned.

Modification Type:MinorLast Reviewed:8/26/2004
Keywords:kbsnaonly kbinfo kbnetwork KB150454 kbAudDeveloper