To create global, domain local, or universal groups: dsadd group “cn=Finance Users,ou=finance,dc=contoso,dc=msft” -samid FinanceUsers -secgrp yes -scope g dsadd group “cn=IT Admin,ou=IT Admin,dc=contoso,dc=msft” –samid ITadmin –secgrp yes –scope g To determine the groups a user is a member of: dsget user UserDN -memberof To modify group membership: Dsmod group groupDN [{-addmbr | -rmmbr | -chmbr} memberDN ...] {-addmbr | -rmmbr | -chmbr} MemberDN ...