User objects can represent employees, customers, or students. Groups are collections of users that permissions or rights can be applied to collectively rather than individually. There are two types of user accounts: local accounts stored on individual computers and domain accounts stored centrally in Active Directory. Domain accounts are replicated across domain controllers for shared management.