Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Sponsored Links



Security Groups & Domain Trusts

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 06-08-2008
Christos Kritikos
 
Posts: n/a
Security Groups & Domain Trusts

Hello,

I have two Windows 2003 domains that trust each other. I want to include
members (groups/users/etc) from domain A in security groups of domain B. So
for example the group DomainB\Managers will have members:
DomainB\manager1, DomainB\manager2 and also DomainA\manager1.

However when trying to edit the group members using AD Users & Computer
console, I am only given the option to add user/groups from the same domain.

is this by design? am i doing something wrong? Is there a way to "bypass"
this problem?

thanks
christos

Reply With Quote
  #2  
Old 06-08-2008
Paul Bergson [MVP-DS]
 
Posts: n/a
Re: Security Groups & Domain Trusts

What type of group are you using? You can create a global domain group from
each forest and users from that forest to the group. Do the same in the
other forest. Then place these global groups into a universal group and
provide the permissions to the universal group. For additional details
review the following link.

http://technet.microsoft.com/en-us/l.../cc772808.aspx

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"Christos Kritikos" <ChristosKritikos@discussions.microsoft.com> wrote in
message news:9914145A-2A65-43F6-93A6-F4D6B1BE02AE@microsoft.com...
> Hello,
>
> I have two Windows 2003 domains that trust each other. I want to include
> members (groups/users/etc) from domain A in security groups of domain B.
> So
> for example the group DomainB\Managers will have members:
> DomainB\manager1, DomainB\manager2 and also DomainA\manager1.
>
> However when trying to edit the group members using AD Users & Computer
> console, I am only given the option to add user/groups from the same
> domain.
>
> is this by design? am i doing something wrong? Is there a way to "bypass"
> this problem?
>
> thanks
> christos
>



Reply With Quote
  #3  
Old 06-08-2008
Christos Kritikos
 
Posts: n/a
Re: Security Groups & Domain Trusts


this url was golden, many thanks! our groups were global, it turns out only
local ones can include members from other domain forests. I will adjust the
design accordingly.

thanks
christos

"Paul Bergson [MVP-DS]" wrote:

> What type of group are you using? You can create a global domain group from
> each forest and users from that forest to the group. Do the same in the
> other forest. Then place these global groups into a universal group and
> provide the permissions to the universal group. For additional details
> review the following link.
>
> http://technet.microsoft.com/en-us/l.../cc772808.aspx
>
> --
> Paul Bergson
> MVP - Directory Services
> MCTS, MCT, MCSE, MCSA, Security+, BS CSci
> 2008, 2003, 2000 (Early Achiever), NT4
>
> http://www.pbbergs.com
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
> "Christos Kritikos" <ChristosKritikos@discussions.microsoft.com> wrote in
> message news:9914145A-2A65-43F6-93A6-F4D6B1BE02AE@microsoft.com...
> > Hello,
> >
> > I have two Windows 2003 domains that trust each other. I want to include
> > members (groups/users/etc) from domain A in security groups of domain B.
> > So
> > for example the group DomainB\Managers will have members:
> > DomainB\manager1, DomainB\manager2 and also DomainA\manager1.
> >
> > However when trying to edit the group members using AD Users & Computer
> > console, I am only given the option to add user/groups from the same
> > domain.
> >
> > is this by design? am i doing something wrong? Is there a way to "bypass"
> > this problem?
> >
> > thanks
> > christos
> >

>
>
>

Reply With Quote
  #4  
Old 06-08-2008
Paul Bergson [MVP-DS]
 
Posts: n/a
Re: Security Groups & Domain Trusts

Yeah that is a typical gotcha. Happens a lot, it can be real confusing

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"Christos Kritikos" <ChristosKritikos@discussions.microsoft.com> wrote in
message news:1A599B10-DF3A-4A04-B12B-9672197B4915@microsoft.com...
>
> this url was golden, many thanks! our groups were global, it turns out
> only
> local ones can include members from other domain forests. I will adjust
> the
> design accordingly.
>
> thanks
> christos
>
> "Paul Bergson [MVP-DS]" wrote:
>
>> What type of group are you using? You can create a global domain group
>> from
>> each forest and users from that forest to the group. Do the same in the
>> other forest. Then place these global groups into a universal group and
>> provide the permissions to the universal group. For additional details
>> review the following link.
>>
>> http://technet.microsoft.com/en-us/l.../cc772808.aspx
>>
>> --
>> Paul Bergson
>> MVP - Directory Services
>> MCTS, MCT, MCSE, MCSA, Security+, BS CSci
>> 2008, 2003, 2000 (Early Achiever), NT4
>>
>> http://www.pbbergs.com
>>
>> Please no e-mails, any questions should be posted in the NewsGroup
>> This posting is provided "AS IS" with no warranties, and confers no
>> rights.
>>
>> "Christos Kritikos" <ChristosKritikos@discussions.microsoft.com> wrote in
>> message news:9914145A-2A65-43F6-93A6-F4D6B1BE02AE@microsoft.com...
>> > Hello,
>> >
>> > I have two Windows 2003 domains that trust each other. I want to
>> > include
>> > members (groups/users/etc) from domain A in security groups of domain
>> > B.
>> > So
>> > for example the group DomainB\Managers will have members:
>> > DomainB\manager1, DomainB\manager2 and also DomainA\manager1.
>> >
>> > However when trying to edit the group members using AD Users & Computer
>> > console, I am only given the option to add user/groups from the same
>> > domain.
>> >
>> > is this by design? am i doing something wrong? Is there a way to
>> > "bypass"
>> > this problem?
>> >
>> > thanks
>> > christos
>> >

>>
>>
>>



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Security Groups & Domain Trusts"
Thread Thread Starter Forum Replies Last Post
Minimum rights required to pull AD Security groups from Trusted Domain pmc101 Active Directory 4 01-09-2010 02:15 PM
question about domain trusts and firewall ports Adam Sandler Active Directory 6 17-08-2010 06:37 PM
How to remove domain trusts aconti Active Directory 4 15-10-2009 03:13 PM
Domain Trusts - how does it work! UselessUser Active Directory 1 08-05-2009 06:51 PM
Trusts with external domain and Domain/Forest Functional Levels MyGposts Active Directory 9 09-12-2008 12:20 PM


All times are GMT +5.5. The time now is 11:10 PM.