Changing Scope of Domain Local Group during Migration

Hello Tech Guys,

Here is the scenario:

Source Domain Local Group is entered in the ACL of the resource and resource is on Source Domain server. Source Domain Local Group has been migrated to Target Domain with sidhistory and during migration group scope has been changed to "Global Group". It means Target Domain Global Group has Sid of Source Domain Local Group under sidhistory attribute.

Now if I add newly created Target Domain user to migrated Target Domain Global Group then user should be able to access resource in Source Domain. However, as per https://activedirectoryfaq.com/2014/10/ad-migration-migrate-domain-local-groups-migrating it says that sidhistory of Target Domain Global Group is removed and access is denied while accessing resource in Source Domain.

As per my understanding, only Sid/Sidhistory of Domain Local Group is not allowed to cross trust boundary. But since during migration scope has been converted to Global Group, it means Sidhistory is now part of Target Domain migrated Global group. Sid/Sidhistory of Global Group is always allowed to cross trust boundary. So logically Target Domain user should be able to access resource in Source Domain.

So am I wrong OR information given in article is incorrect OR did I miss something to understand? Please answer and clarify.

Thanks & Regards,

Peter Dan