What does the IGDLA (AGDLP) model say, and why is it best practice?
Identities go into Global groups (business roles), Global groups go into Domain Local groups (access to one resource), and only the Domain Local group gets the permission.
* Identities → Global group → Domain Local group → Access. *
- Identities (users, computers) are members of…
- Global groups, which represent a business role or job function (
GG_CH_Management), which are members of… - Domain Local groups, which represent one kind of access to one resource (
DL_CH_Management= modify on the Management folder), which receive the… - Access (the permission on the resource).
Microsoft also calls it AGDLP (Accounts, Global, Domain Local, Permissions). It is role-based access control (RBAC) built from nested groups.
Why it pays off: roles and resources change independently. A new employee joins one global group and gets every resource that role needs. A new share gets one domain local group, and you decide which roles to nest into it. Nobody ever sets a permission for an individual user, so an audit only has to read group memberships.
Go deeper:
Wikipedia: AGDLP — the nesting scheme and its variants (AGUDLP for multi-domain forests).
Wikipedia: Role-based access control — the general model IGDLA implements with groups.