Home › Active Directory users and groups › Step 5
Group scopes: local, domain local, global and universal
Step 5 of 9 in Active Directory users and groups · video 5:02
What you will learn
- What group scope controls: membership and where permissions apply
- Membership rules for local, domain local, global and universal groups
- Why universal group membership is published to the global catalog
- When a group can be converted to another scope
About this lesson
A group's scope decides two things: who can be a member and where the group can be given permissions. This lesson compares four scopes. Local groups live on a single member server or workstation and control access to that computer only, although they can hold users and groups from the domain and from trusted domains. Domain local groups are used to grant access to resources and management rights inside their own domain, and can take members from any domain in the forest or from trusted domains. Global groups collect users who have something in common, such as a department or location; they accept members only from their own domain but can be granted permissions anywhere in the forest. Universal groups combine both: members from any domain in the forest and permissions anywhere, with their membership stored in the global catalog, which suits multi-domain forests. A closing summary table includes the rules for converting one scope to another.
Check yourself
1. A global group is created in the domain sales.contoso.com. Can a user from hr.contoso.com be added to it?
No. A global group accepts members only from its own domain (users, computers and other global groups). It can, however, be granted permissions on resources anywhere in the forest.
2. Why are universal groups particularly useful in a forest with several domains?
They accept members from any domain in the forest and can be granted permissions anywhere. Their membership is also replicated to every global catalog server, so it can be read quickly across the enterprise, for example to expand an email list.
3. What prevents a domain local group from being converted to a universal group?
Having another domain local group as a member. A universal group cannot contain domain local groups, so the conversion is allowed only when none is nested inside it.
4. Where can a domain local group be granted permissions?
Only on resources in the domain where the group is defined. That is why domain local groups are the ones placed on the ACLs of that domain's resources, with groups from elsewhere nested inside them.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.