As a best practice, assign resource access to security groups instead of to individual users to simplify administration and ...

As a best practice, assign resource access to security groups—instead of to individual users—to simplify administration and troubleshooting. Resources can include files, folders and shared folders, registry settings, Active Directory Domain Services (AD DS), or applications. For efficiency, create global groups for users based on criteria such as job function or department. Create domain local groups and then place global groups into domain local groups. Assign permissions to the domain local groups as required for your environment. This practice simplifies troubleshooting, and it also simplifies management of changes when they occur, such as when users change job functions.