Using Domain User Account, users have the ability to get to the domain files.
Windows secruity starts with a user account.
The local user is the person who actually uses the account to do the work they are paid to do. A domain user could be a network administrator
A Local user account is a user account that is part of the domain or work group.
Account
In AD (OS server 2000,2003 etc) the all the information is stored in NTDS.DIT database if the server is standalone and not connected to any domain then account information is stored in SAM.
NTDS.DIT database of AD
NTDS.DIT database of AD
user means a name what has already been used.
user account and a computer account
The permissions helps to restrict/monitor the movement(accessing of resources) of the user in the domain.
local users account on local PC. he don't have to log another PC in the network. about domain domain is a logical group of network, all users are create in domain on the server that's y user can log-in in domain any where. u can set policies for user on server not a particular PC.
In domain the adminstrator/ admin group/enterprise admin has rights to create user.
The benefit of having a group policy on domain user account is that you as an administrator can set a restriction or limitation on your users.