Serving the Exchange & Active Directory market since 1997, Imanami's 500+ customers give a great view of who is using AD for what. That's what we blog about.
.
Current Articles | RSS Feed
I had been demonstrating how to manage the creation and automation of AD security groups and distribution lists for months before I realized that I had no idea what the differences were between the three types of Active Directory groups: universal groups (UG), global groups (GG), and domain local groups (DLG). I asked around, poked around the web and found that nobody is really 100% clear on it. Or at least the ones that would talk to me.
With a little work I dug out enough info for this cheatsheet on Active Directory groups:
The short answer is that domain local groups are the only groups that can have members from outside the forest. And use global groups if you have trust, universal groups if you don't care about trust.
Disclaimer: this might still be wrong. But nobody has disputed it yet; thankfully, with good comments, I can always edit the blog post if I have something wrong.
Allowed tags: <a> link, <b> bold, <i> italics