Regardless of whether it is a security or universal group, try to understand the group scope as an extension option of the group in the domain, forest, or tree domain. In AD, there are three group scopes (see Figure 4.29):
- Domain local group: It includes accounts, domain local groups, global groups, and universal groups from the parent's domain local group domain
- Global group: It includes accounts and global groups from the parent's global group domain
- Universal group: It includes accounts, global groups, and universal groups from any domain in the forest where a universal group belongs:
Figure 4.29. Group scopes in ...