GSEC · Question #322
In the AGULP model, who should be assigned permissions and privileges?
The correct answer is B. Local Groups. In the AGULP model, permissions are assigned to Local Groups, which is the 'L' in the acronym Accounts - Global - Universal - Local - Permissions.
Question
In the AGULP model, who should be assigned permissions and privileges?
Options
- AUniversal Groups
- BLocal Groups
- CIndividual User Accounts
- DGlobal Groups
How the community answered
(18 responses)- A6% (1)
- B78% (14)
- C11% (2)
- D6% (1)
Why each option
In the AGULP model, permissions are assigned to Local Groups, which is the 'L' in the acronym Accounts - Global - Universal - Local - Permissions.
Universal Groups aggregate Global groups across domains but are not the endpoint where permissions are assigned in the AGULP model.
AGULP defines a nesting strategy where user Accounts are placed into Global groups, Global groups are nested into Universal groups, Universal groups are nested into Local groups, and permissions are granted to Local groups. This separation allows flexible cross-domain membership while keeping permission assignments manageable at the local level.
Individual user accounts are added to Global groups in AGULP - assigning permissions directly to user accounts bypasses the model and creates an administrative burden.
Global Groups hold user accounts from a single domain and are nested upward into Universal or Local groups, not the target of permission assignments.
Concept tested: AGULP group nesting and permission assignment model
Source: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups
Topics
Community Discussion
No community discussion yet for this question.