What are the three AD group scopes, and how do they differ?
Global groups collect users of their own domain and can be used anywhere in the forest; domain local groups can contain members from anywhere but grant rights only in their own domain; universal groups do both and are best avoided.
| Scope | Can contain | Can be granted rights in |
|---|---|---|
| Global | Users, computers and global groups from the same domain | Any domain of the forest (and trusting domains) |
| Domain local | Members from any trusted domain, including global and universal groups | Its own domain only |
| Universal | Members from any domain of the forest | Any domain of the forest |
The division of labour follows from the table: global groups are good at collecting people (a business role), domain local groups are good at describing access to a resource. Universal groups are flexible, but their full membership is replicated to every Global Catalog server in the forest, which costs replication traffic, so the advice is not to use them unless necessary.
(A forest is the top-level AD boundary: one or more domains that trust each other and share one schema.)
Go deeper:
Microsoft Learn: Group scope — the full table of what each scope can contain and where it can be used.
TechNet Magazine: NTFS Permissions, Part 2 — scopes explained as user groups (global, universal) vs. resource groups (domain local).