Parent Domain Universal Group Not Showing in Child Domain Account "MemberOf" tab

Posted on 2006-03-31
Last Modified: 2010-03-18
Parent Domain mode: Windows 2000 Native, Child Domain mode: Windows Server 2004

If I manage the Universal Group in the Parent Domain I can add the account from the child domain but when I look at the "MemberOf" tab of the child domain account the Parent Domain Universal Group does not show up.

Also, if I manage the child domain user account, "MemberOf" tab and try to add a group I can only select groups from the local domain not the parent domain.

I wrote a VBScript that will dump the group members for an account.  When I run the script against the child domain account it dumps all the group memberships including the parent domain groups.

I tried forcing replication and that did not help.

Looking for any hints as to what to look at next.
Question by:everythingbutthemoo
    LVL 48

    Expert Comment

    Hi everythingbutthemoo,

    when you are in the "memberof" TAB and adding the users, are you telling it to look in the parent domain in the locations box?

    LVL 40

    Expert Comment

    And what are we trying to accomplish here?  Universal Groups are normally used to bring Global Groups together..  

    We discussed this in detail in another thread, which may help you here:

    Author Comment

    The goal is to create an empty root domain by moving all of the groups and users in the parent domain to the child.

    The other goal is not to cripple the company in the process so we will be moving users a few at a time, dept. by dept.

    In order to do this we create the OU and user accounts for the department along with all the groups relevant to that department.  So the HR department's accounts and groups are in the child domain but as is always the case there are a few HR people that need to access objects outside of their department so then need to be members of groups that are yet to be migrated in the parent domain.  Since Global groups can only have accounts from its own domain we had to make all of the global groups into Universal groups.  That way existing parent domain accounts could live side by side with child domain accounts in the same group.  Eventually all of the groups and accounts will be moved to the child domain so this is a transitional thing.

    Beyond that I think we are going to keep using Universal groups and Domain Local groups exclusively in the new domain and not Global groups.  In our size of domain, 1000 users or so, I don't think Global inside of Universal inside of Domain Local makes much sense.  I don't want to have more groups than users and I've see that happen before.  This company is a bit volatile in its acquisitions and sell-offs so I may have to create a new child domain tomorrow and want the ability to assign accounts to groups across the domains.  I like the flexibility of Universal groups and am willing to give up a little bandwidth in the tradeoff.

    I am aware of the Global Catalog implications but I believe that to be negligible especially since now under our 2003 Domain only changes in the Universal group are replicated and not the whole list.  All of our domain controllers are also global catalog servers.

    Anyone that wants to shoot a hole in my logic please feel free...

    As to my original question; that I have answered myself...;en-us;833883
    LVL 40

    Accepted Solution

    Well, the important thing is you got your answer..  I don't see anything wrong with your setup, as long as you understand the implications of replicating traffic between your Global Catalogues...

    and, thanks for the link..

    LVL 40

    Expert Comment

    Did not have to do that, but thanks for closing this out and awarding pts!  :)


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    What Is Threat Intelligence?

    Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

    Downtime reduced, data recovered by utilizing an Experts Exchange Business Account Challenge The United States Marine Corps employs more than 200,000 active-duty Marines with operations in four continents, all requiring complex networking system…
    Are you one of those front-line IT Service Desk staff fielding calls, replying to emails, all-the-while working to resolve end-user technological nightmares? I am! That's why I have put together this brief overview of tools and techniques I use in o…
    In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
    Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    15 Experts available now in Live!

    Get 1:1 Help Now