Skip to main content

Create a Group to Assign Permissions to Access Files

Best practice is to always create a security group, and assign that security group file permissions. You can then assign members or users to that group for file access.

  1. Log into the Active Directory Users and Computers MMC on a Domain Controller or other Computer
  2. Navigate to where you want the new group to be located
  3. Create the security group. Best practice is to create the group as Domain Local for assigning permissions. 
    1. Follow the acronym AGDLP Account > Global Group > Domain Local Group > Permission
    2. It is best to assign users to Global Groups to collect, then assign the Global Groups to the Domain Local groups that have the file permissions.