Domain Local To Global
Global groups cannot be nested across domains.
Domain local to global. However a considerable proportion of the queries submitted to it do specify the domain. User and computer accounts are members of global groups that represent business roles which are members of domain local groups that describe resource. Universal groups where created to support active directory and cross domain memberships and in the early days they came at a price. In addition the scope can both contain and be a member of domain local groups from the same domain.
The domain local group being converted cannot contain another domain local group. Universal group to global or domain local group. Domain local groups also have a scope that extends to the local domain and are used to assign permissions to local resources. For conversion to global group the universal group being converted cannot contain users or global groups from another domain.
As soon as i change the group scope to domain local i can allow us users into the uk group. The domain local scope can contain user accounts universal groups and global groups from any domain. To make a domain controller a global catalog start by launching the active directory sites and services mmc snap in. Contoso has offices in the uk and in the us.
Universal groups are stored in the global catalog and if you changed them let s say by adding a member the whole group was replicated across your active. As local is an officially reserved special use domain name rfc 6762 of february 2013 host names with this top level label are not resolvable in the global domain name system. Nt4 only knew domain local and domain global groups. Stored on the local sam local computer use for security.
A user or computer account from one domain cannot. Domain local group to universal group. Global groups which can prevent some accidental group nestings that may lead to unintended access later on. The fact that domain local groups can t be added to global groups is an intended design effect.
Promoting a domain controller to be a global catalog is a simple change that initiates replication of the partial attribute set for each domain in the forest other than the domain controller s domain. I have created a group in the ad in uk but if the group is set to global i cannot add us users to the group. Members from any domain may be added to a domain local group. Global groups can grant access to anything including files folders in any domain.
Domain local groups accept user accounts from any domain. Agdlp an abbreviation of account global domain local permission briefly summarizes microsoft s recommendations for implementing role based access controls rbac using nested groups in a native mode active directory ad domain.