Windows Domain Local Vs Global
The benefit is that it s easier to keep track of and.
Windows domain local vs global. Nt4 only knew domain local and domain global groups. Global security groups are most often used to organize users who. Put the five user accounts in a group with global scope and add this group to the group having domain local scope. Universal groups where created to support active directory and cross domain memberships and in the early days they came at a price.
In addition the scope can both contain and be a member of domain local groups from the same domain. Members from any domain may be added to a domain local group. Stored on the local sam local computer use for security. For windows 7 the logon has changed and the options are even more complicated.
Initial logon on windows xp allows users to choose a local or domain user account. This will also maximise performance in a multi domain forest. Domain local groups also have a scope that extends to the local domain and are used to assign permissions to local resources. Members from any domain may be added to a domain local group.
In addition the scope can both contain and be a member of domain local groups from the same domain. Universal groups are stored in the global catalog and if you changed them let s say by adding a member the whole group was replicated across your active. When you want to give the five users access to a new printer assign the group with domain local scope permission to access the new printer. The domain local scope can contain user accounts universal groups and global groups from any domain.
To be sure that any membership changes have taken effect ask the users to log off. At logon of a windows xp computer the user can either select the domain or one of many trusted domains or the local computer as can be seen in figure 1. Group membership is evaluated when a user logs on to a domain. Global groups are used collect users into a logical hierarchy to grant permissions for file and folder access using the domain local group.
The domain local scope can contain user accounts universal groups and global groups from any domain.