Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

active directory group with members from multiple domains

Posted on 2009-07-05
5
Medium Priority
?
368 Views
Last Modified: 2013-12-04


Using Windows 2003 active directory with multiple domains in seperate firests (using two-way trusts) is there any way I can create a group on one domain that includes users from another domain?

For example:

CENTRAL domain users:
CENTRAL\Alice
CENTRAL\Bob

BRANCH Domain Users:
BRANCH\Carol
BRANCH\dave

There is a two-way trust between BRANCH and CENTRAL, but they are not in the same forest.

Is there any way to make a group in the CENTRAL domain that includes all four users? When I tried this I found that the membership properties of the group only let me search for users in the CENTRAL domain.
0
Comment
Question by:DrStalker
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 74

Expert Comment

by:Glen Knight
ID: 24782970
Are you running in native 2003 mode?
If so you should be able to use a universal group to achieve this?
0
 

Author Comment

by:DrStalker
ID: 24783046
I'm using windows 2003 as both the domain and forest functional level, for CENTRAL and BRANCH.  Even with a universal group there is no option in the GUI to add users from a domain other than CENTRAL, is there a special way to do this?  

0
 

Accepted Solution

by:
DrStalker earned 0 total points
ID: 24783068
Figured it out - the group needs to be "domain local" which is somewhat counterintuitive. :-)
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 24783076
Glad you got it sorted.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24783157
Two acronyms you may hear with domain locals and what you are dealing with are UGLY and AGLP, I wrote about it here
http://adisfun.blogspot.com/2009/04/ugly-aglp-what-are-they.html
Thanks
Mike
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Suggested Courses

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question