LOGBOOK

HELP

Quiz Entry - updated: 2026.09.29

What are the three AD group scopes, and how do they differ?

Global groups collect users of their own domain and can be used anywhere in the forest; domain local groups can contain members from anywhere but grant rights only in their own domain; universal groups do both and are best avoided.

Scope Can contain Can be granted rights in
Global Users, computers and global groups from the same domain Any domain of the forest (and trusting domains)
Domain local Members from any trusted domain, including global and universal groups Its own domain only
Universal Members from any domain of the forest Any domain of the forest

The division of labour follows from the table: global groups are good at collecting people (a business role), domain local groups are good at describing access to a resource. Universal groups are flexible, but their full membership is replicated to every Global Catalog server in the forest, which costs replication traffic, so the advice is not to use them unless necessary.

(A forest is the top-level AD boundary: one or more domains that trust each other and share one schema.)

Go deeper:

From Quiz: ISLAB / Access Management with Active Directory | Updated: Sep 29, 2026