Both Accounts, Global, Domain Local, Permissions (AGDLP) and Accounts, Global, Universal, Domain Local, Permissions (AGUDLP) are Microsoft's recommendation for effectively using group nesting when assigning permissions. Table 2 presents the flow of assigning permissions with AGDLP and AGUDLP.
Table 2. Assigning permissions with AGDLP and AGUDLP:
AGDLP |
AGUDLP |
Add the Accounts to Global group Add the Global group scope to Domain Local group To Domain Local group assign Permissions |
Add the Accounts to Global group Add the Global group to Universal group Add Universal group to Domain Local group To Domain Local group assign Permissions |