Sign up to access this lesson
Click here to sign up and get access to this lesson!

Saving Progress...
Understanding Groups and Memberships in Active Directory
Active Directory groups and memberships are one of those things you MUST understand in order to administer Active Directory.
At a high level, Active Directory groups are collections of AD Objects. A group’s members can contain users, computers, other groups and more.
Let’s get started!
Create Group in ADUC
To create a group in Active Directory right-click on your desired OU and select New > Group:

The New Object - Group window will appear.
Group Name
Now you need to specify the Group Name. This is the name that will be displayed for the group in Active Directory.

Group Name (pre-Windows 2000)
This will automatically populate the pre-windows 200 group name as well. As the name implies this name is compatible with older versions of Windows Server and is limited to 20 characters.
I am going to name my group “Test Group”
Group Type
There are two types of groups in Active Directory:
- Security
- Distribution
Security
A security group in Active Directory is used to assign permissions to resources with Group Policy.
Distribution
A distribution group in Active Directory is used to create email distribution lists.
We are going to use a Security group in this lesson.
Group Scope
For the group scope, we have three options:
- Domain Local
- Global
- Universal
The scope generally only comes into play when you dealing with multiple domains and trusts. If you are in a single domain environment, nine times out of ten you are going to be fine picking a Global scope. We will still cover the differences here however.
The difference between these comes down to the possible members, memberships of the group, scope conversion (for example, can you change from Global to Universal) and grantable permissions.
If you want to see Microsoft’s documentation on this subject then it can be found here. I’m going to the simplest breakdown for you that I can below:
Scope | Possible Membership of | Grant Permissions | Scope Conversion | Possible Members |
Domain Local | -Domain local groups | -Within the same domain | -To Universal (if no domain local members) | -AD Accounts-Local groups-Global groups-Universal groups ^^ from the same domain, trusted domain, other forests and external domains. |
Global | -AD Accounts-Global groups | -Any domain in the same forest-Trusting domains and forests | -To Universal (if not a member of another global group) | -AD Accounts-Other global groups ^^ from the same domain |
Universal | -Universal Groups ^^ Same Forest -Domain Local groups-Local Groups (computer local not domain) ^^ Same forest or trusting forests | -Any domain in the same forest-Trusting domains and forests | -To Domain Local (if not a member of other universal group)-To Global (if does not contain other Universal Group as a member) | -AD Accounts-Global Groups-Universal Groups ^^ From any domain in the same forest |
In our scenario, we are going to use Global because we are working in a single domain environment and we have no need to add users from other domains or forests.
Creating a group
Once you configued the settings, go ahead and click OK to create the group:

Now you should see the AD Group listed in the Active Directory OU that you created it:

Group Properties
Right-click the group and select Properties:

General Properties
From the General tab, you can convert the group or modify its general information. Click the Members tab.

Delete or add Group Members
Click the Members tab. From here you can see all of the members (if any) of this Active Directory group. Right now there are no members, so let’s add a member by clicking the Add button:

Now you can search for and add your desired user. I am going to use my user account which is “paul.hill”:
Sign up to access the rest of this lesson
You must either log in or sign up to access this lesson.
CURRICULUM
Course Introduction • 1min
0 / 1 lessons complete
Getting Started with Active Directory Domain Services • 52min
0 / 6 lessons complete
Section Overview
Free lesson
Text | 1 min
Installing the ADDS (Active Directory Domain Services) Server Role
Video | 7 min
Promote the Server to a Domain Controller
Video | 7 min
Forests, Trees and Domains
Video | 2 min
Windows Domain Quiz
Quiz | 5 Questions
Lab: Installing the Active Directory Domain Services
Lab | 30 min
Introduction to Active Directory Users & Computers • 1hr 23min
0 / 10 lessons complete
Section Overview
Free lesson
Text | 2 min
Organizational Units (OUs) and Containers
Video | 5 min
Creating, managing and deleting OUs
Video | 5 min
Creating User Accounts with Active Directory
Video | 8 min
Searching for Objects in Active Directory
Video | 6 min
Resetting User Passwords and Unclocking Accounts in Active Directory
Video | 6 min
Understanding Groups and Memberships
Video | 11 min
Disabling and Deleting User Accounts
Video | 6 min
Active Directory Quiz
Quiz | 5 Questions
Lab: Active Directory Users and Computers
Lab | 30 min
Adding a Second Domain Controller • 1hr 30min
0 / 7 lessons complete
Notice of change in Lab Names
Text | 2 min
Section Overview
Free lesson
Video | 2 min
Promoting Our Second Domain Controller
Video | 13 min
Flexible Single Master Operation (FSMO) Roles Overview
Free lesson
Video | 4 min
Transferring FSMO (Flexible Single Master Operations) Roles
Video | 5 min
Adding a Second Domain Controller Quiz
Quiz | 5 Questions
Lab: Adding a Second Domain Controller
Lab | 60 min
Active Directory Backups • 1hr 24min
0 / 5 lessons complete
Creating an Active Directory / System State Backup
Video | 4 min
Restoring an Active Directory Backup
Video | 7 min
Creating and Restoring Active Directory Snapshots
Video | 8 min
Active Directory Backups Quiz
Quiz | 5 Questions
Lab: Active Directory Backups
Lab | 60 min
How to Administrate Active Directory with Windows PowerShell • 1hr 58min
0 / 7 lessons complete
Enabling Script Execution for PowerShell
Video | 6 min
Listing AD Users with PowerShell
Video | 14 min
Creating AD Users with PowerShell
Free lesson
Video | 10 min
Creating User Accounts from a CSV (Comma Separated Value) File
Video | 15 min
Move All Disable Users to Disabled Users OU with PowerShell
Video | 8 min
AD PowerShell Quiz
Quiz | 5 Questions
Lab: ADUC PowerShell Automation
Lab | 60 min
Administrating AD SS (Active Directory Sites and Services) • 1hr 3min
0 / 5 lessons complete
Active Directory Sites and Services - Section Overview
Free lesson
Video | 8 min
Configuring Our ITFROUTE01 Server to act as a Router
Video | 11 min
Configuring Active Directory Sites and Services
Video | 9 min
Administrating AD SS Quiz
Quiz | 5 Questions
Lab: Configure ADDS Between Two Subnets
Lab | 30 min
Active Directory Trusts • 54min
0 / 5 lessons complete
Window Trusts Explained
Free lesson
Video | 6 min
Configuring DNS Settings for Active Directory Trusts
Video | 6 min
Establish a Two-way Active Directory Trust
Video | 7 min
Active Directory Trusts Quiz
Quiz | 5 Questions
Lab: Establish a two-way AD Trust
Lab | 30 min
Modifying the Active Directory Schema • 43min
0 / 3 lessons complete
Add Custom Attributes to Active Directory Users
Video | 8 min
Active Directory Schema Quiz
Quiz | 5 Questions
Lab: Extending the Active Directory Schema
Lab | 30 min
Course Conclusion • 1min
0 / 1 lessons complete