Holds members only from the domain it belongs to, yet can be granted access anywhere in that forest or in domains that trust it; one of the three AD group scopes.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Global group in context, with comparison tables and the common traps.
Terms in this definition
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- Forest
The highest-level AD container and security boundary. Its domain trees, one or more, all use one schema, configuration and global catalog.
Related terms
- Domain Admins
A built-in global group that has complete control over its domain. Its members are local administrators on all computers joined to that domain.
- Group Policy Creator Owners
Anyone in this built-in global group may add new Group Policy Objects to the domain, and afterwards may edit only those they themselves made.
- Protected Users
Members get fixed protections: four-hour TGTs, no delegation, no Digest, CredSSP or NTLM, and no RC4 or DES during Kerberos pre-authentication. Keep computer and service accounts out of this global group.