Domain Local Group Vs Global Group
Global groups cannot be nested across domains.
Domain local group vs global group. Often used to assign permissions for access to resources i e. Can be a member of global groups of the same domain domain local groups or universal groups of any domain in the forest or trusted domains. You cannot add foreign users domain local global or universal groups to a domain global group and so if you create another domain in your forest you cannot simply add users or groups from that new domain to your existing security structure. The benefit is that it s easier to keep track of and.
Because of its limited scope however members can only be assigned permissions within the domain in which this group is created. Can contain users computers and groups from same domain but not universal groups. If you want a specific global group to have permissions to an object you can just nest them into that domain local group and now that global group has access to those objects. Global groups are used collect users into a logical hierarchy to grant permissions for file and folder access using the domain local group.
Domain local global and universal are group scopes which allow you to use groups in different ways to assign permissions. It can be useful to give each domain local group a name that is meaningful to the it operations team e g. A user or computer account from one domain cannot be nested within a global group in another domain. The scope of a group determines from where in the network you can assign permissions to the group.
The difference between domain local and global groups is that user accounts global groups and universal groups from any domain can be added to a domain local group.