Home › Active Directory users and groups › Step 5

Group scopes: local, domain local, global and universal

Step 5 of 9 in Active Directory users and groups · video 5:02

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

A group's scope decides two things: who can be a member and where the group can be given permissions. This lesson compares four scopes. Local groups live on a single member server or workstation and control access to that computer only, although they can hold users and groups from the domain and from trusted domains. Domain local groups are used to grant access to resources and management rights inside their own domain, and can take members from any domain in the forest or from trusted domains. Global groups collect users who have something in common, such as a department or location; they accept members only from their own domain but can be granted permissions anywhere in the forest. Universal groups combine both: members from any domain in the forest and permissions anywhere, with their membership stored in the global catalog, which suits multi-domain forests. A closing summary table includes the rules for converting one scope to another.

Good to know: strictly, Active Directory has three group scopes: domain local, global and universal. Local groups belong to individual computers. A global group takes members from its own domain only, whatever the summary table in the video suggests.

Check yourself

Answer in your head first, then open each question to see the answer.

1. A global group is created in the domain sales.contoso.com. Can a user from hr.contoso.com be added to it?

No. A global group accepts members only from its own domain (users, computers and other global groups). It can, however, be granted permissions on resources anywhere in the forest.

2. Why are universal groups particularly useful in a forest with several domains?

They accept members from any domain in the forest and can be granted permissions anywhere. Their membership is also replicated to every global catalog server, so it can be read quickly across the enterprise, for example to expand an email list.

3. What prevents a domain local group from being converted to a universal group?

Having another domain local group as a member. A universal group cannot contain domain local groups, so the conversion is allowed only when none is nested inside it.

4. Where can a domain local group be granted permissions?

Only on resources in the domain where the group is defined. That is why domain local groups are the ones placed on the ACLs of that domain's resources, with groups from elsewhere nested inside them.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Managing Groups, Computers and OUs

4.5★ · 1,445 students on Udemy

See the course on Udemy
← Group types: security and distribution groupsNext: Group nesting with IGDLA and IGUDLA →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.