How to Create Active Directory Groups

Create Active Directory security and distribution groups, choose the correct scope, assign membership, and verify permissions safely.

On this page

Link to What Are Active Directory Groups?What Are Active Directory Groups?

An Active Directory (AD) group is a directory object that aggregates users, computers, or other groups into a single unit, simplifying access control and resource management. Groups in AD are not just containers; they play a central role in how permissions, policies, and communication lists are managed across the enterprise.

There are two main types of groups in AD:

  • Security Groups: These are used to assign permissions to resources (e.g., files, printers) and user rights (e.g., logon permissions). Only security groups show up in access control lists (ACLs) and can be used to control access within AD-integrated applications.
  • Distribution Groups: These are intended solely for email distribution lists and cannot be used to assign permissions. They are typically leveraged by email systems such as Microsoft Exchange but play no role in resource authorization.

In addition to type, each group has a scope that determines its membership options and where it can be granted permissions:

  • Universal: Can contain users, groups, and computers from any domain in the forest. Permissions assigned to universal groups apply anywhere in the forest.
  • Global: Can contain users, groups, and computers from its own domain only, but can be given permissions in any domain within the forest.
  • Domain Local: Can contain members from any trusted domain, but permissions assigned to domain local groups apply only within their own domain.

The intersection of group type and scope underpins AD’s flexible—and potentially complex—authorization model. For example, a global security group might represent all engineers in a domain, while a domain local security group represents access to a specific shared resource.

Link to Permissions: Who Can Create Groups?Permissions: Who Can Create Groups?

Creating a group in Active Directory requires the appropriate permissions. By default, only members of the Domain Admins group and a few other privileged accounts have the right to create groups anywhere in the domain. However, organizations rarely grant Domain Admin rights for routine group management.

Instead, rights to create and manage groups are often delegated to non-admins at a finer granularity, typically at the organizational unit (OU) level. This allows, for example, a helpdesk team to manage groups relevant to their business unit without granting them excessive administrative privileges.

Delegation is performed using the Delegation of Control Wizard in Active Directory Users and Computers:

  1. Right-click the target OU and select "Delegate Control."
  2. Use the wizard to specify the users or groups to whom control will be delegated.
  3. Select "Create, delete, and manage groups" to grant only the necessary group management permissions.

This granular, OU-scoped delegation is a core administrative best practice—it limits risk, supports least privilege, and streamlines operational workflow.

Link to Step-by-Step: Creating Groups in Active DirectoryStep-by-Step: Creating Groups in Active Directory

Active Directory supports both manual and automated group creation methods.

Link to Using the GUI (Active Directory Users and Computers)Using the GUI (Active Directory Users and Computers)

  1. Open Active Directory Users and Computers.
  2. Navigate to the desired OU.
  3. Right-click within the OU, select New → Group.
  4. Enter the Group name and (optionally) description.
  5. Select the Group scope (Domain Local, Global, Universal).
  6. Select the Group type (Security or Distribution).
  7. Click OK to create the group.

This process initializes the group object within the schema, applying your selected scope, type, and location.

Link to Using PowerShellUsing PowerShell

The New-ADGroup cmdlet is the official method for scriptable and automated group creation:

powershell
New-ADGroup -Name "TestGroup" -GroupScope Global -GroupCategory Security -Path "OU=MyOU,DC=domain,DC=com" -Description "Description of the group"

This example creates a global security group named "TestGroup" in the specified OU with a description. Bulk operations can be performed by combining New-ADGroup with data sources like CSV files, allowing rapid provisioning of many group objects as required.

Link to Choosing Group Type and Scope: Security, Distribution, and BeyondChoosing Group Type and Scope: Security, Distribution, and Beyond

Link to Security vs. Distribution GroupsSecurity vs. Distribution Groups

  • Security groups are the only groups usable for resource permissions—such as assigning access to filesystems or applications. If you intend any form of access management, use a security group.
  • Distribution groups are strictly for email and workflow communications. They cannot be assigned permissions and will not appear when you set access rights on a file, folder, or other resource.

Choosing the wrong type can lead to operational failures; for example, using a distribution group to gate file access simply won’t work.

Link to Scope: Universal, Global, Domain LocalScope: Universal, Global, Domain Local

The group scope determines:

  • Where the group’s members can originate from.

  • Where the group itself can be assigned permissions.

  • Global groups: Best for grouping users with the same function within a single domain (e.g., "NYC_Sales"). They can be assigned permissions anywhere but only include members from their own domain.

  • Domain Local groups: Used to assign permissions to resources within a single domain. Members can come from any trusted domain.

  • Universal groups: Allow membership and assignment across domains; useful in multi-domain or forest environments, but larger universal groups can increase AD replication traffic.

Some scope/type changes are restricted after creation if the group contains certain members or if functional level requirements aren't met, so design groups thoughtfully at the outset.

Link to Best Practices for Group ManagementBest Practices for Group Management

Link to Naming Conventions and OrganizationNaming Conventions and Organization

Clear, consistent naming is vital for scalable group management. Recommended approaches:

  • Prefix or suffix with location, department, or function (e.g., NYC_HR_Read)
  • Use concise, business-relevant terms
  • Avoid cryptic or generic names that obscure purpose

Link to The AGDLP ModelThe AGDLP Model

AGDLP (“Accounts → Global Groups → Domain Local Groups → Permissions”) is the industry pattern for reliable, maintainable group design:

  • Place user accounts (A) in global groups (G)
  • Add global groups to domain local groups (DL)
  • Assign permissions to domain local groups (P)

This separates group management by function, simplifies permission reviews, and enhances auditing and delegation capabilities.

Link to Nesting ConsiderationsNesting Considerations

Group nesting—placing groups within groups—can simplify access management and align with business structure. However, excessive or poorly planned nesting increases complexity, can introduce permission anomalies, and complicates troubleshooting. Only nest groups to reflect true organizational hierarchy or shared access requirements.

Link to Common Misconceptions and PitfallsCommon Misconceptions and Pitfalls

  • Distribution groups assign permissions: False. Only security groups can be assigned permissions or added to ACLs.
  • Only admins can create groups: With proper delegation to OUs, non-admin users (like HR, Helpdesk) can manage group creation in their areas as required.
  • Scope or type can always be changed post-creation: Certain scope changes (like converting from global to domain local or universal scope) may be restricted based on group membership or domain/forest functional level.
  • Nesting always helps: Over-nesting or careless nesting complicates permission tracking and may create unintended access paths.

Understanding these points prevents failed permissions assignments, minimizes administrative overhead, and reduces security exposure.

Link to Summary and Further ResourcesSummary and Further Resources

Active Directory group management underpins enterprise access control and business logic. Always choose a security group (with appropriate scope: global, domain local, or universal) when you require permissions assignment. Delegate group management responsibly to limit risk. Use consistent naming and established nesting paradigms like AGDLP to ensure clarity and scalability.

For authoritative details and deeper exploration:

  • [Active Directory Security Groups — Microsoft Learn]
  • [New-ADGroup PowerShell Reference — Microsoft Learn]
  • [Delegation of Control Wizard — Microsoft Learn]

Link to SourcesSources