Local Groups and Microsoft Cluster Server

This article was previously published under Q241796
This article has been archived. It is offered "as is" and will no longer be updated.
You can use local groups to assign resource permissions in Microsoft Windows NT-based domains. This strategy does not work well with Cluster Server because resources may fail over but local groups may not. The Cluster Administrator tool, by design, prevents you from assigning local groups in most cases, and displays the following error message when you attempt to do so:
Cluster Administrator Standard Extension
Access to a cluster file share can be granted/denied only to domain users and groups. Please remove any local users or groups from the permissions dialog box.
After you receive this error message, you must remove the permission line that caused the error message before you can continue.
Keep the following items in mind when you are implementing Cluster Server:
  • Avoid installing Cluster Server on domain controllers if performance is an issue.
  • Do not attempt to use local groups to assign permissions, even though the local groups are shared between domain controllers.
  • Use global groups only, and only from the master domain in a multiple-domain scenario.
In Microsoft Windows 2000, you can use domain local groups on member servers. If both nodes of the cluster are members of the same domain, you can use domain local groups to grant access to cluster resources.
mscs server cluster

Article ID: 241796 - Last Review: 10/22/2013 00:40:35 - Revision: 3.3

  • Microsoft Windows 2000 Advanced Server
  • Microsoft Windows NT Server 4.0 Enterprise Edition
  • kbnosurvey kbarchive kbdocerr kbinfo KB241796