Home › Active Directory users and groups › Step 6
Group nesting with IGDLA and IGUDLA
Step 6 of 9 in Active Directory users and groups · video 4:47
What you will learn
- The IGDLA nesting pattern and what each letter stands for
- How IGUDLA adds universal groups in multi-domain forests
- Granting cross-organisation access through a domain local rule group
- Delegating membership changes with the Managed By tab
About this lesson
Putting groups inside other groups is called nesting, and this lesson shows the recommended pattern. In IGDLA, identities (user and computer accounts) go into global groups that represent business roles; those role groups go into domain local groups that represent a management rule, such as read access to a set of folders; and the domain local group is what appears on the resource's access control list. In a multi-domain forest the pattern becomes IGUDLA, with a universal group gathering global groups from several domains. A worked example gives Contoso salespeople and auditors from Woodgrove Bank, a trusted organisation, read access to a Sales folder through a domain local group called ACL-Sales-Read. The result is one place to manage who holds each role and another to manage who may read the data, even if it spreads across several servers. The lesson finishes with the Managed By tab and the option that lets a manager update a group's membership.
Check yourself
1. In IGDLA, which group is added to the ACL of the shared folder?
The domain local group, which represents the access rule (for example ACL-Sales-Read). Users sit in global role groups that are nested into it, so the ACL itself rarely needs to change.
2. Auditors from a trusted external domain need read access to your Sales folder. How would you grant it following the lesson's pattern?
Put the auditors in a global group in their own domain, add that group to your domain local group (such as ACL-Sales-Read), and grant the domain local group Read on the folder. Domain local groups can accept global groups from trusted domains.
3. What does the U in IGUDLA stand for, and when is it used?
Universal groups. In a forest with several domains, global groups from each domain are placed in one universal group, which is then added to domain local groups in the domains that hold the resources.
4. What does ticking Manager can update membership list on a group's Managed By tab allow?
It lets the user or group named as manager add and remove members themselves. This suits environments where department managers control their own groups instead of asking IT for every change.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.