Domain Local Vs Global
Global groups cannot be nested across domains.
Domain local vs global. Should not be used to assign permissions on ad objects e g. Jika fungsi itu lebih besar daripada nilai fungsi lainnya di seluruh domain set elemen terbesar di codomain. Members from any domain may be added to a domain local group.
Domain local groups also have a scope that extends to the local domain and are used to assign permissions to local resources. Members can come from any domain. In addition the scope can both contain and be a member of domain local groups from the same domain.
Ou s user accounts etc because they cannot be evaluated in other domains. Domain local groups are used to assign permissions to local resources such as files and printers. The difference between domain local and global groups is that user accounts global groups and universal groups from any domain can be added to a domain local group.
Domain local groups accept user accounts from any domain. Universal groups are stored in the global catalog and if you changed them let s say by adding a member the whole group was replicated across your active. Members of this group can access resources in any domain.
Nt4 only knew domain local and domain global groups. Intended for use on objects not directly in ad such as file shares printer queues etc. Members can only come from the local domain.
Members can be from any domain in the forest. Universal groups universal security groups are most often used to assign permissions to related resources in multiple domains. The global scope can contain user accounts and global groups from the same domain and can be a member of universal and domain local groups in any domain.