Understanding AGDLP and AGUDLP

Both Accounts, Global, Domain Local, Permissions (AGDLP) and Accounts, Global, Universal, Domain Local, Permissions (AGUDLP) are Microsoft's recommendation for effectively using group nesting when assigning permissions. Table 2 presents the flow of assigning permissions with AGDLP and AGUDLP.

Table 2. Assigning permissions with AGDLP and AGUDLP:

AGDLP

AGUDLP

Add the Accounts to Global group

Add the Global group scope to Domain Local group

To Domain Local group assign Permissions

Add the Accounts to Global group

Add the Global group to Universal group

Add Universal group to Domain Local group

To Domain Local group assign Permissions

Get Windows Server 2016 Administration Fundamentals now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.