Solved

Domain local group does not appear on domain member computers

Posted on 2004-08-25
6
333 Views
Last Modified: 2010-04-19
1. I have a printer that is attached to a workstation and would like to share it by granting access to a Domain Local Group. However, at the workstation, Domain Local Group do not appear to be available for selection under security tab when I try to share it. But Domain Global Group does show up.

I thought that Domain Local Group are available within the domain only so that all the domain members should be able to see them.

2. Can a Global Group be a member of another Global Group? I cannot make it what way, but it seems that a Global Group can be a member of Domain Local Group.

Lastly, if I have a folderresiding on another machine which is a domain member, what is the best way to share it. I was thinking of creating a Domain Local Group and granting rights to this group, then, add the already established Global Group to this Domain Local Group, but then I got stuck with the issue in #1...
0
Comment
Question by:SC2002Admin
  • 3
  • 2
6 Comments
 
LVL 82

Accepted Solution

by:
oBdA earned 500 total points
Comment Utility
Your domain is still running in "Windows 2000 Mixed" mode. Domain Local Groups and nesting of global groups are only possible in (at least) the "Windows 2000 Native" domain functional level. If you don't have Windows NT4 BDCs (and don't plan to introduce any), you can raise the functional level to W2k Native. If you don't have Windows 2000 DCs either, you can switch to Server 2003 domain and forest functional level.
Here's more information:
HOW TO: Raise Domain and Forest Functional Levels in Windows Server 2003
http://support.microsoft.com/?kbid=322692
0
 
LVL 6

Expert Comment

by:karel_jespers
Comment Utility
for 1. you must create on your workstation a local group ..
and
the domain local group is only available to host recources on dc's
0
 
LVL 82

Expert Comment

by:oBdA
Comment Utility
karel_jespers,
the scope of a domain local group in a W2k(3) domain is *only* limited to DCs while the domain is still running in mixed mode. Once the domain is running in native mode, domain local groups will be available for permission assignment on any domain member that's running W2k or later.

Domain Local Groups Cannot Be Used in Mixed-Mode Domain
http://support.microsoft.com/?kbid=296369
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 6

Expert Comment

by:karel_jespers
Comment Utility

that is right, but is it necessairy for him to go native mode, only to fix that sharing problem of a printer
0
 
LVL 82

Expert Comment

by:oBdA
Comment Utility
karel_jespers,
I'd see it the other way: Assuming that there are no downlevel DCs, why stay in mixed mode? Domain local groups where developed to make administration easier, so if possible, you might as well profit from it.
Apart from that, SC2002Admin was querying about features of an AD domain that he knew "should be there", so telling him that "the domain local group is only available to host recources on dc's" is rather misleading.

SC2002Admin,
before I forget it, the approach in your last question is the correct one.
0
 

Author Comment

by:SC2002Admin
Comment Utility
Thaks oBdA, I got it working the way I thought it would work now.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now