I was recently trying to research into nested groups, and I ran a gpresult under my standard domain (non-elevated) account. I noticed 2 AD security groups that my account was inheriting that made no sense...
I looked into them, and they're Universal security groups that--I'm guessing--were made incorrectly because they're for obscure folder shares, thousands of miles away. Now, they're being replicated to every domain in the entire forest. Not only that, our group for all domain users are in the "Members" attribute.
Basically, every single user in every domain in the forest is a member of these obscure share permission groups.
Has anyone else ran into problems that have been caused by this? I understand this is probably just unnecessary replication traffic if anything, but have you experienced things like this causing major issues? I don't have rights to change it, but I can request if it's a problem...
Thanks!