Solved

active directory group with members from multiple domains

Posted on 2009-07-05
5
348 Views
Last Modified: 2013-12-04


Using Windows 2003 active directory with multiple domains in seperate firests (using two-way trusts) is there any way I can create a group on one domain that includes users from another domain?

For example:

CENTRAL domain users:
CENTRAL\Alice
CENTRAL\Bob

BRANCH Domain Users:
BRANCH\Carol
BRANCH\dave

There is a two-way trust between BRANCH and CENTRAL, but they are not in the same forest.

Is there any way to make a group in the CENTRAL domain that includes all four users? When I tried this I found that the membership properties of the group only let me search for users in the CENTRAL domain.
0
Comment
Question by:DrStalker
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 74

Expert Comment

by:Glen Knight
ID: 24782970
Are you running in native 2003 mode?
If so you should be able to use a universal group to achieve this?
0
 

Author Comment

by:DrStalker
ID: 24783046
I'm using windows 2003 as both the domain and forest functional level, for CENTRAL and BRANCH.  Even with a universal group there is no option in the GUI to add users from a domain other than CENTRAL, is there a special way to do this?  

0
 

Accepted Solution

by:
DrStalker earned 0 total points
ID: 24783068
Figured it out - the group needs to be "domain local" which is somewhat counterintuitive. :-)
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 24783076
Glad you got it sorted.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24783157
Two acronyms you may hear with domain locals and what you are dealing with are UGLY and AGLP, I wrote about it here
http://adisfun.blogspot.com/2009/04/ugly-aglp-what-are-they.html
Thanks
Mike
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question