If you ever try to move your server, ie server
dies, you restore to another server, and you do not have the exact same local
groups defined, watch out! I suggest always using domain level groups. That way
if you ever have to restore to another server the security accounts are still
legit. I think Best Practices also state to stay with domain level if possible.