Solved

Adding user from a trusted domain to a security group?

Posted on 2010-11-09
5
5,884 Views
Last Modified: 2012-05-10
Gang,

     Thanks for checking out my post.  I have a question that I'm too lazy to look up, so I hope my EE friends can help me out.  I have:

* Active Directory 2k3 - Running 2000 Native Mode
* All Win2k3 DCs (Win2k3 w/SP2).  
* An external transitive trust with another Win2k3 domain (I believe it's running 2k3 native).

To set up the scenario:

* My domain is called MINE.local
* Their domain is called THERIS.local

     I manage MINE.local, but would like to share resources in MINE.local with users in the THEIRS.local domain.  The trust is cool, but I need a bit of advice on how to add users to groups.

I tested the 3 types of groups (Domain Global, Domain Universal, and Domain Local).  If I attempt to add users to the Domain Local group, I can see THEIRS.local.  If I attempt to add the users to Domain Global and Domain Universal groups, I can only see internal trusts (my prod. domain is in an empty forest root).  My questions are:

* Why is that?
* If I convert either the Domain Global and/or Domain Univeral groups, what are the caveats, and what should I look for?

Thanks

-fedsig

     
0
Comment
Question by:fedsig
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 27

Expert Comment

by:KenMcF
ID: 34098281
Take a look at these links, they explain the different types of groups in AD>

•Domain Local Group: Use this scope to grant permissions to domain resources that are located in the same domain in which you created the domain local group. Domain local groups can exist in all mixed, native and interim functional level of domains and forests. Domain local group memberships are not limited as you can add members as user accounts, universal and global groups from any domain. Just to remember, nesting cannot be done in domain local group. A domain local group will not be a member of another Domain Local or any other groups in the same domain.
•Global Group: Users with similar function can be grouped under global scope and can be given permission to access a resource (like a printer or shared folder and files) available in local or another domain in same forest. To say in simple words, Global groups can be use to grant permissions to gain access to resources which are located in any domain but in a single forest as their memberships are limited. User accounts and global groups can be added only from the domain in which global group is created. Nesting is possible in Global groups within other groups as you can add a global group into another global group from any domain. Finally to provide permission to domain specific resources (like printers and published folder), they can be members of a Domain Local group. Global groups exist in all mixed, native and interim functional level of domains and forests.
•Universal Group Scope: these groups are precisely used for email distribution and can be granted access to resources in all trusted domain as these groups can only be used as a security principal (security group type) in a windows 2000 native or windows server 2003 domain functional level domain. Universal group memberships are not limited like global groups. All domain user accounts and groups can be a member of universal group. Universal groups can be nested under a global or Domain Local group in any domain.


http://www.tech-faq.com/active-directory-groups.html
http://technet.microsoft.com/en-us/library/bb727067.aspx
0
 
LVL 27

Accepted Solution

by:
KenMcF earned 500 total points
ID: 34098307
0
 

Author Comment

by:fedsig
ID: 34098473
Sweet!  Now, do you know of any caveats on switching back and fourth?  

From what I read, domain local groups aren't to be used to assign permissions to objects within Active Directory, but work for external objects (coputers, printers, etc).  The group I'm considering converting to a Domain Local group (from a Universal Group) is used only for folder-level permissions to a specific folder.  

It makes sense that I can't add foreign users to a Universal group b/c my forest shares a GC, and external trusts do not share GCs.  Universal Groups look like they're stored in the GC, but not DL groups.

Regards,

fedsig
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34098534
I would not switch the groups back, you should design the groups on each end so there will be no need to switch the group scopes. Mike Kline who is on EE has a good blog post about the setup of groups.


http://adisfun.blogspot.com/2009/04/ugly-aglp-what-are-they.html
0
 

Author Closing Comment

by:fedsig
ID: 34098720
Thanks
0

Featured Post

Revamp Your Training Process

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DSRM password 5 42
Script to find any empty OU and nested OU in Active Directory 2 64
Changing logon server question 5 67
Windows 2012 R2 DFS Replication 12 47
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question