We use the lousy nested structure for shared folder ntfs permissions where a domain local group contains a universal which contains a global and the global has the users. I want to find a way to create the 3 groups required when a new folder is setup, then add users to the global group.
Also, does anyone have any good references on the latest best practices for share permissions? I know when/why dl groups are used, but why use the nesting scheme for every file share on 20+ file servers?