Home › Active Directory users and groups › Step 4

Group types: security and distribution groups

Step 4 of 9 in Active Directory users and groups · video 2:22

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Every Active Directory group has a type and a scope; this lesson deals with the type. Security groups have a security identifier (SID) and can appear in access control lists, so they are used to grant permissions on resources; they can also serve as email distribution lists. Distribution groups are not security-enabled and exist for email applications. New groups are created as security groups by default, which is why many organisations never create anything else. The lesson explains the cost of that habit: each security group a user belongs to adds its SID to the user's access token, making the token larger than it needs to be. It then covers converting between the two types at any time, and what happens to existing permissions when a security group becomes a distribution group. Finally it points out that a new membership takes effect only in a fresh access token, so a signed-in user must sign out and back in.

Check yourself

Answer in your head first, then open each question to see the answer.

1. You need a group to grant Modify permission on a shared folder. Which group type must it be?

A security group. Only security-enabled groups have a SID that can be used in an access control list; a distribution group cannot be used to manage security.

2. What happens to existing permissions if you convert a security group to a distribution group?

They stop working for the group. The ACL entries still hold its SID, but a distribution group's SID is no longer placed in members' access tokens, so those entries no longer match anyone.

3. Why is a distribution group the better choice for a list used only for email?

A security group gets a SID that is added to every member's access token, so groups used only for mail make tokens bigger for no benefit. A distribution group has no such effect.

4. You add a signed-in user to a security group, but she still cannot open the folder the group has access to. Why?

Her access token was built when she signed in and does not include the new group yet. She must sign out and sign in again so that a new token with the updated membership is issued.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Managing Groups, Computers and OUs

4.5★ · 1,445 students on Udemy

See the course on Udemy
← User profiles, home folders and folder redirectionNext: Group scopes: local, domain local, global and universal →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.