Read the documentation for your Active Directory for an explanation of group concepts under Windows Server.
In Active Directory, contacts, computers, and groups can be collected into groups for which the access to resources can be regulated not only within a domain but across domains.
We distinguish between two group types:
-
Security groups
Permissions are granted through security groups. User accounts, computers, and other groups are added to security groups and which makes administration easier. Security groups are also used for email distribution groups.
-
Distribution groups
Distribution groups can be used as mail-enabled distribution groups. Distribution groups do not have any security.
In addition, a group area is defined for each group type. Permitted group types are:
-
Universal
Groups within this scope are described as universal groups. Universal groups can be used to make cross-domain permissions available. Universal group members can be user accounts and groups from all domains in one domain structure.
-
Local domain
Groups in this scope are described as groups of the local domain. Local groups are used when permissions are issued within the same domain. Members of a domain local group can be user accounts, computers, or groups in any domain.
-
Global
Groups within this scope are described as global groups. Global groups can be used to make cross-domain permissions available. Members of a global group are only user accounts, computers, and groups belonging to the global group’s domain.
Related topics
- Managing memberships in Active Directory groups
- Creating and editing Active Directory groups
- Validity of group memberships
- Adding Active Directory groups to Active Directory groups
- Assigning Active Directory account policies to Active Directory groups
- Assigning secretaries to Active Directory groups
- Assigning extended properties to Active Directory groups
- Deleting Active Directory groups
- Moving Active Directory groups
- Displaying the Active Directory group overview
- Displaying Azure Active Directory groups for Active Directory groups
- Synchronizing single objects