Win 2003 - 2008 Trust

kingcastle
kingcastle used Ask the Experts™
on
Hi
I have a trust relationship setup ok between 2003 AD and 2008 AD and it validates all ok. But when i goto the 2003AD and try to add a user from the 2008AD to a group it only shows me the 2003AD and not both, i checked and this is the same from the other side.
why is this the case and how can o resolve.

cheers
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Mike ThomasConsultant
Top Expert 2010

Commented:
when tryng to add a user or group click the locations button, you should be able to select the trusted domain and then users/groups from that domain.

Author

Commented:
thats what im doing but the other domain is not listed there, weird thing is if i log off at thr ctrl alt del screen i get the option to logon onto either domain??
Mike ThomasConsultant
Top Expert 2010
Commented:
How long has it been since you created the trust? the fact that you see it as a log on option suggests everything is in place and working OK.

You could try adding the trusted domains DNS zone as a secondary zone on your DNS servers, this is something I do as standard so i'm not sure if it might be a factor or not but could be worth trying for the 10 mins it wil take you to do.

Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Author

Commented:
Will try and post back cheers

Author

Commented:
ok tried that same, thing do i need to leave it while before checking it again?

cheers
What is the exact type of trust you create?
If this trust is not bidirectional you don't see user from both sides.
Otherwise you have to create two trust relationships (one outgoing and another ingoing).
Post detailed info about your trust creation and we suggest the solution.

Commented:
Did you use forwarder or secondary zones for name resolution between the two domains?
what happens when you validate the trust from either side?

Regards,
Shahid

Author

Commented:
i have created a two way trust, it validates fine no problem and yes i have tried both conditional forwarders and secondary zones neither work. i think this has something to do with win2003 and win2008 trusts.
i notice that if i goto some groups ie dhcp admins for example and goto memebers and add, i can change location and pick the othe domain but that is the only place i can do that. for example i only see the relavent domain if i try to change locatio for adding a user to the domain admin group for example.

cheers
Commented:
Did you make the id which you are using for migration member of administrator,enterprise admin & domain admin in both the domains.

Until dns issue is resolved trust will not work.

Just Go thru below link,might be something prove helpful.

http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/4520ad76-6514-4155-aa12-11b73c7b5bcc

http://support.microsoft.com/kb/179442

http://blogs.techrepublic.com.com/window-on-windows/?p=500
Commented:
Keep in mind that your dhcp admins is probably a "Domain Local" group instead of "global group" and the reason why you can see both domain when trying to add members to it. This is by design. Just like when you open a "global group" from your win2k8 domain and trying to add members to it, you should only see your win2k8 domain but not win2k3. This is because you cannot add global group from another domain to your win2k8 domain's global group. If some global group in your win2k8 domain must be leverage and wants to add member in the win2k3 domain, all you need to do is convert that specific win2k8 global group to a domain locat group then you would be abe to see both domain as you can add global group from both domain into a Domain Local group.

Author

Commented:
guys i didnt realise you had to type the domains names into the source and targert part of ADMT.
i thought they had to be on the drop down list once i typed them in away it went. im goin award points based on being pointed in the right direction.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial