Domain Local Group Vs Universal
Often used to assign permissions for access to resources i e.
Domain local group vs universal. There are three group scopes and they are domain local global and universal. Direct assignment or access permissions on files and printer etc. The differences between these are listed below. Universal groups do not care about trust.
The scope of a group determines where in the active directory network we can use the group to assign permissions to the group. Domain local groups orange global groups green universal groups light blue nesting of domain local groups to begin with a domain local group can be a member of another domain local group within the same domain. Rules that govern when a group can be added to another group different domain. Can contain users and groups global and universal from any domain in the forest.
A domain local group cannot be nested within a global or a universal group. Domain local global and universal are group scopes which allow you to use groups in different ways to assign permissions. In native mode a group type can be converted freely between security groups and distribution groups. It can be useful to give each domain local group a name that is meaningful to the it operations team e g.
Domain local groups can be converted to a universal group provided that there are no other domain local groups in its membership. Domain global groups can be a member of domain local groups and domain universal groups in any domain. For conversion to domain local group the universal group being converted cannot be a member of any universal group or a domain local group from another domain. The scope of a group determines from where in the network you can assign permissions to the group.
If the domain local group does have other domain local groups as members then these must be removed from the membership before a conversion is made. Domain local groups domain local. Use domain global groups to organize users who share similar access requirements and make them member of the domain local groups you use to grant access to resources.