Domain Local Group Vs Universal
Domain global groups can be a member of domain local groups and domain universal groups in any domain.
Domain local group vs universal. The scope of a group determines from where in the network you can assign permissions to the group. Can contain users and groups global and universal from any domain in the forest. The differences between these are listed below.
It can be useful to give each domain local group a name that is meaningful to the it operations team e g. In native mode a group type can be converted freely between security groups and distribution groups. Domain local groups can grant access to resources on the same domain.
Domain local groups domain local. Domain local global and universal are group scopes which allow you to use groups in different ways to assign permissions. Universal groups can be a member of domain local groups or other universal groups but not global groups.
If the domain local group does have other domain local groups as members then these must be removed from the membership before a conversion is made. Use domain global groups to organize users who share similar access requirements and make them member of the domain local groups you use to grant access to resources. A domain local group cannot be nested within a global or a universal group.
There are three group scopes and they are domain local global and universal. In addition local users and. Domain local groups orange global groups green universal groups light blue nesting of domain local groups to begin with a domain local group can be a member of another domain local group within the same domain.
Domain local groups can be converted to a universal group provided that there are no other domain local groups in its membership. Often used to assign permissions for access to resources i e. The scope of a group determines where in the active directory network we can use the group to assign permissions to the group.