LOGBOOK

HELP

Quiz Entry - updated: 2026.09.29

In a single-domain forest the group scopes make no technical difference. Why use IGDLA there anyway?

Because the strict pattern keeps administration clean: permissions are always on domain local groups and people are always in global groups, so nobody can grant permissions "the wrong way round".

Microsoft designed the scheme for multi-domain forests, where the scope rules matter. In a single domain you could use global groups for everything without any performance cost.

The value is organisational. With a fixed rule ("roles are GG, resource access is DL, users never go on ACLs") the permission model stays readable as it grows: you can tell from a group's name and scope what it is for, and a resource's access list only ever contains a few DL groups. It also means the model already works if the company later adds a second domain.

Go deeper:

From Quiz: ISLAB / Access Management with Active Directory | Updated: Sep 29, 2026