Domain Local Vs Global Vs Universal Groups
Members can be from any domain in the forest.
Domain local vs global vs universal groups. Domain local group memberships are not limited as users can add members as user accounts and universal and global groups from any domain. Nesting cannot be done in a domain local group. Domain local groups can be a member of domain local groups from the same domain. A domain local group will not be a member of another domain local or any other groups in the same domain.
However you cannot nest a global group from domain a into domain b https www. If you have trusts configured between domains etc you can nest a universla group in domain a into either a universal group or a global group within domain b. In addition the scope can both contain and be a member of domain local groups from the same domain. Permissions can be assigned in any domain.
Universal group is a security or distribution group that contains users groups and computers from any domain in its forest as members. Stored on the local sam local computer use for security. Members from any domain may be added to a domain local group. Domain local groups can grant access to resources on the same domain.
Also you can use a. The domain local scope can contain user accounts universal groups and global groups from any domain. A domain local group cannot be nested within a global or a universal group. The reason being that you can add domain global and domain universal groups from any domain to a domain local group.
Global group is a group that can be used in its own domain in member servers and in workstations of the domain and in trusting domains. The global scope can contain user accounts and global groups from the same domain and can be a member of universal and domain local groups in any domain. Members from any domain may be added. Members must be in the same domain as the group.
You can give universal security groups rights and permissions on resources in any domain in the forest. Universal groups are one step higher and provide the ability of group nesting interdomain and forests. Use domain local groups to grant access to resources such as you file systems.