Domain Group Type Security Distribution
You can also control who receives group policy settings.
Domain group type security distribution. Therefore if you are trying to convert a dlg into a ug the dlg cannot have any other domain local groups as members table 3 3 outlines the possibilities and restrictions of changing the scope of a group. On the create group wizard in the self service portal the group type option will be set to distribution so groups can only be created as distribution lists. This type of group is what happens when a distribution list falls in love with an active directory security group. A domain local security group has a value of 2147483644 4 2147483648.
Users will not be able to change the group type to a security group. To determine the group type you add the first number 2 4 or 8 to the second number 2147483648 if the group is a security group 0 if it s a distribution group. This security group includes the following changes since windows server 2008. A distribution group can be used for sending emails to a group of users.
A domain local distribution group has a value of 4 4 0. However the returned value is in raw format. This simplifies administration by allowing you to set permissions once on multiple. We cannot use distribution groups for this purpose and a security group has all the capabilities of a distribution group.
By using a security group we can collect a group of user accounts in a department and assign them access to a shared folder. Essentially it is the above two types of groups married together. The grouptype attribute returns the type of group. For example a universal security group cannot have a domain local group as a member.
Make semi private security type as default while group creation from ssp. This group has the special privilege to take ownership of any object in the directory or any resource on a domain controller. Essentially it is the above two types of groups married together. Security groups allow you to manage user and computer access to shared resources.