Solved

active directory group with members from multiple domains

Posted on 2009-07-05
5
344 Views
Last Modified: 2013-12-04


Using Windows 2003 active directory with multiple domains in seperate firests (using two-way trusts) is there any way I can create a group on one domain that includes users from another domain?

For example:

CENTRAL domain users:
CENTRAL\Alice
CENTRAL\Bob

BRANCH Domain Users:
BRANCH\Carol
BRANCH\dave

There is a two-way trust between BRANCH and CENTRAL, but they are not in the same forest.

Is there any way to make a group in the CENTRAL domain that includes all four users? When I tried this I found that the membership properties of the group only let me search for users in the CENTRAL domain.
0
Comment
Question by:DrStalker
  • 2
  • 2
5 Comments
 
LVL 74

Expert Comment

by:Glen Knight
ID: 24782970
Are you running in native 2003 mode?
If so you should be able to use a universal group to achieve this?
0
 

Author Comment

by:DrStalker
ID: 24783046
I'm using windows 2003 as both the domain and forest functional level, for CENTRAL and BRANCH.  Even with a universal group there is no option in the GUI to add users from a domain other than CENTRAL, is there a special way to do this?  

0
 

Accepted Solution

by:
DrStalker earned 0 total points
ID: 24783068
Figured it out - the group needs to be "domain local" which is somewhat counterintuitive. :-)
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 24783076
Glad you got it sorted.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24783157
Two acronyms you may hear with domain locals and what you are dealing with are UGLY and AGLP, I wrote about it here
http://adisfun.blogspot.com/2009/04/ugly-aglp-what-are-they.html
Thanks
Mike
0

Featured Post

Networking for the Cloud Era

Join Microsoft and Riverbed for a discussion and demonstration of enhancements to SteelConnect:
-One-click orchestration and cloud connectivity in Azure environments
-Tight integration of SD-WAN and WAN optimization capabilities
-Scalability and resiliency equal to a data center

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

791 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question