Domain Local Group Scope
In addition the scope can both contain and be a member of domain local groups from.
Domain local group scope. Members from any domain may be added to a domain local group. Domain local global and universal are group scopes which allow you to use groups in different ways to assign permissions. File permissions local machine file permissions domain file server file printer share permissions can be mail enabled can use to assign mailbox permissions permissions on active directory objects machine. For conversion to domain local group the universal group being converted cannot be a member of any universal group or a domain local group from another domain.
If your scope of resource usage is several domains linked by trust relationships use global groups instead. The differences between these are listed below. Domain local groups also have a scope that extends to the local domain and are used to assign permissions to local resources. The domain local scope can contain user accounts universal groups and global groups from any domain.
In native mode a group type can be converted freely between security groups and distribution groups. Domain local groups domain local. There are three group scopes and they are domain local global and universal. The domain guests group applies to versions of the windows server operating system listed in the active directory default security groups table.
Group scope location can act as distribution list. Security groups are what handle rights and resource permissions whereas distribution groups are used to group together like users such as for a distribution list in microsoft exchange. This would be local domain local global and universal for group scope while the group types consist of security groups and distribution groups. The difference between domain local and global groups is that user accounts global groups and universal groups from any domain can be added to a domain local group.
The scope of a group determines where in the active directory network we can use the group to assign permissions to the group.