Group scope needs to be defined during the group setup process. But with operational requirement or infrastructure changes, there can be occasions where this already defined scope is not valid anymore. In such a situation, instead of setting up a new group, it can be converted into a different scope. It doesn't mean you can convert any scope to any group. There are some rules to follow:
Group Scope | Domain local | Global | Universal |
Domain local | N/A | X |
√(only if there are no other domain local groups as members) |
Global | X | N/A |
√(only if it's not a member of other global groups) |
Universal |
√ |
√(only if there are no other universal groups as members) |
N/A |