Global Security Vs Domain Local
The reason being that you can add domain global and domain universal groups from any domain to a domain local group.
Global security vs domain local. Permissions can be assigned only in the local domain. Domain global groups can only contain users and domain global groups from the same domain. Domain local groups can grant access to resources on the same domain. The domain local scope can contain user accounts universal groups and global groups from any domain.
Use domain local groups to grant access to resources such as you file systems. Global groups cannot be nested across domains. The difference between domain local and global groups is that user accounts global groups and universal groups from any domain can be added to a domain local group. Intended for use on objects not directly in ad such as file shares printer queues etc.
Should not be used to assign permissions on ad objects e g. Members from any domain may be added to a domain local group. Domain local groups can be a member of domain local groups from the same domain. The scope of a group determines from where in the network you can assign permissions to the group.
During a disaster recovery exercise. Members can be from any domain in the forest. With domain global groups permissions can be assigned to resources in any domain. Because of its limited scope however members can only be assigned permissions within the domain in which this group is created.
Local security groups apply security settings locally and are used for localised administration etc global security groups are your domain groups which are created with the installation of ad as you would know these groups when operating at native mode are able to be nested into other groups etc within your domain environment. Domain local global and universal are group scopes which allow you to use groups in different ways to assign permissions. Ou s user accounts etc because they cannot be evaluated in other domains. Local groups will work even if the network becomes unavailable e g.
Domain local groups accept user accounts from any domain. In addition the scope can both contain and be a member of domain local groups from the same domain.