Domain Local Group Vs Global Group
You cannot add foreign users domain local global or universal groups to a domain global group and so if you create another domain in your forest you cannot simply add users or groups from that new domain to your existing security structure.
Domain local group vs global group. The difference between domain local and global groups is that user accounts global groups and universal groups from any domain can be added to a domain local group. Domain local global and universal are group scopes which allow you to use groups in different ways to assign permissions. If you want a specific global group to have permissions to an object you can just nest them into that domain local group and now that global group has access to those objects.
Because of its limited scope however members can only be assigned permissions within the domain in which this group is created. Global groups cannot be nested across domains. Can be a member of global groups of the same domain domain local groups or universal groups of any domain in the forest or trusted domains.
Global groups are used collect users into a logical hierarchy to grant permissions for file and folder access using the domain local group. The benefit is that it s easier to keep track of and. Can contain users computers and groups from same domain but not universal groups.
Direct assignment or access permissions on files and printer etc. If you use a domain local group you can add groups from other domains whereas if. A user or computer account from one domain cannot be nested within a global group in another domain.
The scope of a group determines from where in the network you can assign permissions to the group.