Link to home
Start Free TrialLog in
Avatar of romatlo
romatlo

asked on

Can I add a Global Security group as a member of another Global Security group?

Can I add a Global Security group as a member of another Global Security group?
Like nested groups?

Example:
SG1 and SG2
Can I add SG2 as a member of SG1?  I keep getting An Object name SG2 can not be found...etc even though I am pointing to the correct domain and OU location.

Does anyone know if this is possible for what I am doing wrong?
Avatar of tigermatt
tigermatt
Flag of United Kingdom of Great Britain and Northern Ireland image

You certainly can nest security groups in that fashion - in a single-domain environment at least. If SG2 is a member within SG1, then members of SG2 will inherit all permissions which SG1 is granted. Useful in a lot of cases - but can get out of hand quite quickly!

If the security group isn't being picked up, press the Advanced button when you go to add it to SG1, then ensure you are searching the whole domain and press "Find Now". The SG should appear in the list, where you can select it, then press OK three times to add it as a member of the group.

-tigermatt
ASKER CERTIFIED SOLUTION
Avatar of Shift-3
Shift-3
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of romatlo
romatlo

ASKER

I am trying all that and it is not picking it up.  I have tried this in two different domain setups.  I must be doing something wrong.  I have done this many times before I am know must be doing something silly.
I have attached a picture of my search and show my OU structure, etc.

I know the groups are there because I have search AD with other programs and it finds them.

HELP!!
AD.JPG
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of romatlo

ASKER

I am using W2K Mixed.  I read through the tech net article and it does say it is disabled.

I guess except for Built-in groups such as Administrators and Domain Admins, since they are nested?
Avatar of romatlo

ASKER

I must have been using Native when I was nesting in other tests.  I will try native and check back.  Thanks!!
In that case, you have the problem which has been described above. If all your Domain Controllers support it, you must move to the 2000 Native level to get nesting support.
Avatar of romatlo

ASKER

Yep, I just Raised it and it works.  Thanks!  I did not realize that this was disabled in that mode.  
Avatar of romatlo

ASKER

Thanks guys