Create a Group to Assign Permissions to Access Files
Best practice is to always create a security group, and assign that security group file permissions. You can then assign members or users to that group for file access.
- Log into the Active Directory Users and Computers MMC on a Domain Controller or other Computer
- Navigate to where you want the new group to be located
- Create the security group. Best practice is to create the group as Domain Local for assigning permissions. 
- Follow the acronym AGDLP Account > Global Group > Domain Local Group > Permission
- It is best to assign users to Global Groups to collect, then assign the Global Groups to the Domain Local groups that have the file permissions.
 
