Group strategy in Active Directory: scopes, AGDLP and clean membership
Security and distribution groups, the three group scopes and what each can contain, the AGDLP pattern (and its multi-domain variant), naming, when a membership change actually reaches a user, token size, and reviewing who is in what.
- Level
- Intermediate
- Length
- About 50 minutes
- Contents
- 3 lessons · final exam
- Status
- Published · updated 1 Oct 2026
Skills you'll practise
- Choose the right group type and scope for a given purpose
- Design access with AGDLP: role groups (global) nested into resource groups (domain local) that hold the permissions
- Explain when a membership change takes effect for a signed-in user and what to tell them
- Recognize token-size risk from excessive group membership and nesting
- Run and document a periodic group membership review
Course outline
- 1.Group types and scopesLesson · 16 min
- 2.AGDLP: role groups, resource groups, permissionsLesson · 18 min
- 3.When membership takes effect, token size and reviewsLesson · 16 min
- 4.Group strategy in Active Directory: scopes, AGDLP and clean membership: knowledge checkKnowledge check · 14 questions
- 5.Final exam4 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Microsoft Learn: Active Directory security groups (group types, scopes and conversion)
- Microsoft Learn: Nesting groups (archived Windows Server 2003 reference)
- Microsoft Learn: Group membership changes do not update over some VPN connections (how group membership reaches tickets and tokens)
- Microsoft Learn: Kerberos authentication problems when a user belongs to many groups (MaxTokenSize)
- General Windows Server / Microsoft 365 administration practice
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.