Domain Local Ad Group
Domain local groups domain local.
Domain local ad group. To modify groups in ad you must be a member of the account operators group the domain admins group or the enterprise admins group or you must have been delegated the appropriate authority. If the domain local group does have other domain local groups as members then these must be removed from the membership before a conversion is made. Can be a member of global groups of the same domain domain local groups or universal groups of any domain in the forest or trusted domains.
As you can see on this graphic users or computers from domain a can become members of one or more domain local groups. Next you create a domain local group for the. Now there is the option to nest a local group with users or computers of other domains by using a trusted domain of the same forest.
The reason being that you can add domain global and domain universal groups from any domain to a domain local group. When members of this group sign in as local guests on a domain joined computer a domain profile is created on the local computer. Use domain local groups to grant access to resources such as you file systems.
Domain local global and universal are group scopes which allow you to use groups in different ways to assign permissions. It can be useful to give each domain local group a name that is meaningful to the it operations team e g. Can contain users computers and groups from same domain but not universal groups.
To use a domain local group you first determine which users have similar job responsibilities in your enterprise. In the long history of humankind and animal kind too those who learned to collaborate and improvise most effectively have prevailed charles darwin. Domain local groups can be converted to a universal group provided that there are no other domain local groups in its membership.
Domain local groups can be a member of domain local groups from the same domain. The scope of a group determines from where in the network you can assign permissions to the group. Direct assignment or access permissions on files and printer etc.