Regardless of whether it is a security or universal group, try to understand the group scope as an extension option of the group in a forest, tree domain, or child domain. In an AD, there are three group scopes (see Figure 5.26):
- The domain local group includes accounts, domain local groups, global groups, and universal groups from the parent's domain local group domain.
- The global group includes accounts and global groups from the parent's global group domain.
- The universal group includes accounts, global groups, and universal groups from any domain in the forest where a universal group belongs:

Figure 5.26: Group ...