Parent Domain Universal Group Not Showing in Child Domain Account "MemberOf" tab

Parent Domain mode: Windows 2000 Native, Child Domain mode: Windows Server 2004

If I manage the Universal Group in the Parent Domain I can add the account from the child domain but when I look at the "MemberOf" tab of the child domain account the Parent Domain Universal Group does not show up.

Also, if I manage the child domain user account, "MemberOf" tab and try to add a group I can only select groups from the local domain not the parent domain.

I wrote a VBScript that will dump the group members for an account.  When I run the script against the child domain account it dumps all the group memberships including the parent domain groups.

I tried forcing replication and that did not help.

Looking for any hints as to what to look at next.
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Hi everythingbutthemoo,

when you are in the "memberof" TAB and adding the users, are you telling it to look in the parent domain in the locations box?

Fatal_ExceptionSystems EngineerCommented:
And what are we trying to accomplish here?  Universal Groups are normally used to bring Global Groups together..  

We discussed this in detail in another thread, which may help you here:
everythingbutthemooAuthor Commented:
The goal is to create an empty root domain by moving all of the groups and users in the parent domain to the child.

The other goal is not to cripple the company in the process so we will be moving users a few at a time, dept. by dept.

In order to do this we create the OU and user accounts for the department along with all the groups relevant to that department.  So the HR department's accounts and groups are in the child domain but as is always the case there are a few HR people that need to access objects outside of their department so then need to be members of groups that are yet to be migrated in the parent domain.  Since Global groups can only have accounts from its own domain we had to make all of the global groups into Universal groups.  That way existing parent domain accounts could live side by side with child domain accounts in the same group.  Eventually all of the groups and accounts will be moved to the child domain so this is a transitional thing.

Beyond that I think we are going to keep using Universal groups and Domain Local groups exclusively in the new domain and not Global groups.  In our size of domain, 1000 users or so, I don't think Global inside of Universal inside of Domain Local makes much sense.  I don't want to have more groups than users and I've see that happen before.  This company is a bit volatile in its acquisitions and sell-offs so I may have to create a new child domain tomorrow and want the ability to assign accounts to groups across the domains.  I like the flexibility of Universal groups and am willing to give up a little bandwidth in the tradeoff.

I am aware of the Global Catalog implications but I believe that to be negligible especially since now under our 2003 Domain only changes in the Universal group are replicated and not the whole list.  All of our domain controllers are also global catalog servers.

Anyone that wants to shoot a hole in my logic please feel free...

As to my original question; that I have answered myself...;en-us;833883
Fatal_ExceptionSystems EngineerCommented:
Well, the important thing is you got your answer..  I don't see anything wrong with your setup, as long as you understand the implications of replicating traffic between your Global Catalogues...

and, thanks for the link..


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Fatal_ExceptionSystems EngineerCommented:
Did not have to do that, but thanks for closing this out and awarding pts!  :)

It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Networking

From novice to tech pro — start learning today.