Link to home
Start Free TrialLog in
Avatar of Thor2923
Thor2923Flag for United States of America

asked on

can a univeral distribution group have a global security group as a member and the members of the Global group receive email?

I have a universal email distribution group and a Global security group with an email address assigned to it has been added to it. I am not sure if it was always a security group or if someone converted it. Anyway, individual users added to the universal group are getting emails but the members of the Global group are not. I just cannot recall the basic rules. Can a Global group even belong to a Universal group? That could be my problem right there....btw we at using Exchange 2016 with active directory 2012
Avatar of ScriptAddict
Flag of United States of America image

I believe that at least for security groups the setup that is recommended is:

Accounts get assigned to global groups, global groups get assigned to universal groups and universal groups get assigned to domain local groups.  

If that helps at all.

I must note this is security groups.  I don't recall distribution groups.
Did you mail-enable the security group?
Avatar of timgreen7077

Make sure that the security group is mail-enabled. If its not you can run the below

Enable-DistributionGroup -Identity "group name"
Avatar of Thor2923


The first distribution group shows "Mail Universal Distribution Group" and all users that are individually added receive emails. There is a distribution group under it that also shows as "Mail Universal Distribution Group" under Exchange 2010 Recipient Type Details, but none of the second groups members receive email when the top group is emailed. There is also a Global Group that displays as "Mail NON-Universal Group" in Exchange 2010 and members of that group do not receive emails sent to the top group. I am assuming the way all the groups are listed under Recipient Type Details means they are all mail enabled. Very strange.
If you have nested groups you need to be sure that the sender is allowed to send to the nested group along with the parent group. If they can send to the parent DL, but there is also a nested DL, they will also need to be allowed to send to that one also.
I was thinking along those lines too. All I can see is that both the top and sub Universal groups require sender to be "authenticated" but it is not limited to specific users. Please see attachment
Avatar of timgreen7077

Link to home
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
author is the comments on this ticket was helpful, please assign points and close ticket.