Learn how to a build a cloud-first strategyRegister Now


Parent Domain Universal Group Not Showing in Child Domain Account "MemberOf" tab

Posted on 2006-03-31
Medium Priority
Last Modified: 2010-03-18
Parent Domain mode: Windows 2000 Native, Child Domain mode: Windows Server 2004

If I manage the Universal Group in the Parent Domain I can add the account from the child domain but when I look at the "MemberOf" tab of the child domain account the Parent Domain Universal Group does not show up.

Also, if I manage the child domain user account, "MemberOf" tab and try to add a group I can only select groups from the local domain not the parent domain.

I wrote a VBScript that will dump the group members for an account.  When I run the script against the child domain account it dumps all the group memberships including the parent domain groups.

I tried forcing replication and that did not help.

Looking for any hints as to what to look at next.
Question by:everythingbutthemoo
  • 3
LVL 48

Expert Comment

ID: 16347050
Hi everythingbutthemoo,

when you are in the "memberof" TAB and adding the users, are you telling it to look in the parent domain in the locations box?

LVL 40

Expert Comment

ID: 16347916
And what are we trying to accomplish here?  Universal Groups are normally used to bring Global Groups together..  

We discussed this in detail in another thread, which may help you here:


Author Comment

ID: 16374509
The goal is to create an empty root domain by moving all of the groups and users in the parent domain to the child.

The other goal is not to cripple the company in the process so we will be moving users a few at a time, dept. by dept.

In order to do this we create the OU and user accounts for the department along with all the groups relevant to that department.  So the HR department's accounts and groups are in the child domain but as is always the case there are a few HR people that need to access objects outside of their department so then need to be members of groups that are yet to be migrated in the parent domain.  Since Global groups can only have accounts from its own domain we had to make all of the global groups into Universal groups.  That way existing parent domain accounts could live side by side with child domain accounts in the same group.  Eventually all of the groups and accounts will be moved to the child domain so this is a transitional thing.

Beyond that I think we are going to keep using Universal groups and Domain Local groups exclusively in the new domain and not Global groups.  In our size of domain, 1000 users or so, I don't think Global inside of Universal inside of Domain Local makes much sense.  I don't want to have more groups than users and I've see that happen before.  This company is a bit volatile in its acquisitions and sell-offs so I may have to create a new child domain tomorrow and want the ability to assign accounts to groups across the domains.  I like the flexibility of Universal groups and am willing to give up a little bandwidth in the tradeoff.

I am aware of the Global Catalog implications but I believe that to be negligible especially since now under our 2003 Domain only changes in the Universal group are replicated and not the whole list.  All of our domain controllers are also global catalog servers.

Anyone that wants to shoot a hole in my logic please feel free...

As to my original question; that I have answered myself... http://support.microsoft.com/default.aspx?scid=kb;en-us;833883
LVL 40

Accepted Solution

Fatal_Exception earned 2000 total points
ID: 16377417
Well, the important thing is you got your answer..  I don't see anything wrong with your setup, as long as you understand the implications of replicating traffic between your Global Catalogues...

and, thanks for the link..

LVL 40

Expert Comment

ID: 16404774
Did not have to do that, but thanks for closing this out and awarding pts!  :)


Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A brief overview to explain gateways, default gateways and static routes OR NO - you CANNOT have two default gateways on the same server, PC or other Windows-based network device. In simple terms a gateway is formed when a computer such as a serv…
This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question