This my only real weakness, whenever I start to look at resources that explain the difference between group scopes, I get a headache. I just can't get the difference between them. This is what I get:
Domain Local - Can contain users and groups from any domain, but can only be assigned permissions on the domain they were created.
Global - Can contain only users and groups from the domain they were created in, but can be members of Domain Local groups, to get access to resources in other domains.
Universal - Only avaialable as security groups, if the domain is not running in Win 2000 mixed (are they available in Win 2k3 interim?). Can contain users and groups from any domain, and can be assigned permissions in any domain.
Am I getting this right, or am I way out there? I might fail, just because I cant get the difference between group scopes.