Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Interforest  Authentication

Posted on 2007-11-27
2
Medium Priority
?
376 Views
Last Modified: 2012-05-05
Hi

Can someone explain this please.

Two win2003 forests linked via a forest trust.
I understand users in either forest can access resources in the other forest; however, I have a share with default permissions applied (except for share permission which is everyone Full Control) so how can a user from the other forest access this share without me explicitly giving permission to him or OtherDomain\Users group?

I thought the domain users groups were members of each other but I checked and this is not the case.

Thanks


 
0
Comment
Question by:Nael_Shahid
2 Comments
 
LVL 23

Expert Comment

by:ormerodrutter
ID: 20358407
You need to add the User Group (from the other forest) in your NTFS ACLs.
0
 

Accepted Solution

by:
Nael_Shahid earned 0 total points
ID: 20358431
Yes but that is exactly the issue.

I have not added them into the ACL but they still have access. I want to know why.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
The article explains the process to deploy a Self-Service password reset portal I developed a few years ago. Hopefully, it will prove useful to someone.  Any comments, bug reports etc. are welcome...
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

577 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question