Domain Local Ad Group
The domain guests group applies to versions of the.
Domain local ad group. To modify groups in ad you must be a member of the account operators group the domain admins group or the enterprise admins group or you must have been delegated the appropriate authority. As you can see on this graphic users or computers from domain a can become members of one or more domain local groups. Can be a member of global groups of the same domain domain local groups or universal groups of any domain in the forest or trusted domains. Can contain users computers and groups from same domain but not universal groups.
Direct assignment or access permissions on files and printer etc. To use a domain local group you first determine which users have similar job responsibilities in your enterprise. Often used to assign permissions for access to resources i e. It can be useful to give each domain local group a name that is meaningful to the it operations team e g.
The domain guests group includes the domain s built in guest account. Domain local global and universal are group scopes which allow you to use groups in different ways to assign permissions. In the long history of humankind and animal kind too those who learned to collaborate and improvise most effectively have prevailed charles darwin. The scope of a group determines from where in the network you can assign permissions to the group.
If the domain local group does have other domain local groups as members then these must be removed from the membership before a conversion is made. Domain local groups can be a member of domain local groups from the same domain. Use domain local groups to grant access to resources such as you file systems. Domain local groups domain local.
The reason being that you can add domain global and domain universal groups from any domain to a domain local group. Domain local groups can be converted to a universal group provided that there are no other domain local groups in its membership. Now there is the option to nest a local group with users or computers of other domains by using a trusted domain of the same forest.