Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
Also called accounts, global, domain local, permissions.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AGDLP in context, with comparison tables and the common traps.
Terms in this definition
- Pattern
A reusable answer to a recurring problem that places building blocks in context, explaining when, how and why to apply them and what compromises are involved.
Related terms
- AADDC Computers
Container built into an Entra Domain Services managed domain, holding joined VMs' computer accounts, with a GPO of its own.
- Access Control Assistance Operators
Members of this built-in domain-local group may remotely query a computer's resources for their permissions and authorisation attributes.
- Access this computer from the network
Accounts holding this user right can connect across the network, to SMB shares for instance.
- Access tier
Setting for block blobs in standard accounts (Hot, Cool, Cold or Archive). Cooler tiers cost less to store but more to access.
- Access token
A credential an application hands to an API or other resource to prove what it has been authorised to do for a signed-in user. It deals with permissions, unlike the ID token, which records the sign-in itself.
- Account lockout policy
Locks accounts after a set number of failed sign-ins, using domain settings for threshold, duration and counter reset. Thresholds run from 0 to 999, and 0 disables lockout.
- Account Operators
A built-in group allowed to create and manage most user, group and computer accounts, except those of administrators. Microsoft advises leaving it without members.
- Account SAS
Shared access signature created with an account key. One token may cover multiple services (ss), resource types (srt) and permissions (sp), service-level operations included, but turning off Shared Key authorisation blocks it.