Home › Active Directory users and groups › Step 6

Group nesting with IGDLA and IGUDLA

Step 6 of 9 in Active Directory users and groups · video 4:47

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Putting groups inside other groups is called nesting, and this lesson shows the recommended pattern. In IGDLA, identities (user and computer accounts) go into global groups that represent business roles; those role groups go into domain local groups that represent a management rule, such as read access to a set of folders; and the domain local group is what appears on the resource's access control list. In a multi-domain forest the pattern becomes IGUDLA, with a universal group gathering global groups from several domains. A worked example gives Contoso salespeople and auditors from Woodgrove Bank, a trusted organisation, read access to a Sales folder through a domain local group called ACL-Sales-Read. The result is one place to manage who holds each role and another to manage who may read the data, even if it spreads across several servers. The lesson finishes with the Managed By tab and the option that lets a manager update a group's membership.

Check yourself

Answer in your head first, then open each question to see the answer.

1. In IGDLA, which group is added to the ACL of the shared folder?

The domain local group, which represents the access rule (for example ACL-Sales-Read). Users sit in global role groups that are nested into it, so the ACL itself rarely needs to change.

2. Auditors from a trusted external domain need read access to your Sales folder. How would you grant it following the lesson's pattern?

Put the auditors in a global group in their own domain, add that group to your domain local group (such as ACL-Sales-Read), and grant the domain local group Read on the folder. Domain local groups can accept global groups from trusted domains.

3. What does the U in IGUDLA stand for, and when is it used?

Universal groups. In a forest with several domains, global groups from each domain are placed in one universal group, which is then added to domain local groups in the domains that hold the resources.

4. What does ticking Manager can update membership list on a group's Managed By tab allow?

It lets the user or group named as manager add and remove members themselves. This suits environments where department managers control their own groups instead of asking IT for every change.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Managing Groups, Computers and OUs

4.5★ · 1,445 students on Udemy

See the course on Udemy
← Group scopes: local, domain local, global and universalNext: Default administrative groups in Active Directory →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.