Link to home
Start Free TrialLog in
Avatar of NTGuru705
NTGuru705Flag for United States of America

asked on

Apply Domain Local Groups on Member Servers

I have a problem that I just discovered.  It seems that I am unable to apply permissions for any Domain Local Groups on any of my member servers?  I can apply fine on the domain controllers but not on any member server... is there something special I need to to to allow domain local groups to be applied on the member servers?

If I was not clear I am trying to apply security to directories/files.

Thank you for your help.

Austin Henderson
Avatar of oBdA
oBdA

Your domain is probably still running in mixed mode. For domain local groups to be available on member servers, you'll need to switch your domain to native mode, otherwise they'll behave like local groups on NT4 DCs.
As long as you don't have any leftover NT4 BDCs or plan to add NT4 BDCs, you should be able to switch over without problems.

Members of a Domain Local Group Are Not Granted Rights
http://support.microsoft.com/?kbid=260534

Modes Supported by Windows 2000 Domain Controllers
http://support.microsoft.com/?kbid=186153

Group Type and Scope Usage in Windows
http://support.microsoft.com/?kbid=231273
Avatar of NTGuru705

ASKER

This is right on..
Here is the problem.. we are running an Exchange 5.5 box that at one time was a BDC (technically still is) for my NT 4 domain that is now mixed mode with three 2K DCs and this NT 4 box.... there is no way for me to go native because of this box is there... ?
ASKER CERTIFIED SOLUTION
Avatar of oBdA
oBdA

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
The problem is I cant do that.  It is a NAS device and the Domain Local groups are on one of my domain controllers... the disk space that I bought is where I need to apply the permissions... and there are a ton of groups that have been created for this purpose. Previously we had no troubles because the disks that these permissions were applied to were ON the DC.. but we are taking that burdon off the DC and putting it on the NAS device... thus my problem has been revealed.

Perhaps my exchange upgrade is quicker that planned.
I am looking at using ... UPromote..

http://utools.com/UPromote.asp

Anyone have any experience with this tool.. if it were not for Exchange 5.5 running on this box I would just pull the trigger on this tool but I hesitate because of Exch 5.5 on it.

Thanks
Well, that's exactly the tool I meant, but I don't have any experience with it, sorry; and I guess you found http://utools.com/Exchange.asp already.