Solved

adding user in one domain to a group in a different domain in AD

Posted on 2011-02-17
10
695 Views
Last Modified: 2012-05-11
We have two domains that were previously two different companies. I have been told by level 3 engineering that "a sufficient trust has been built". I was asked to put a user in what I will call domain ABC.COM into a group in domain XYZ.COM. I am logged into my workstation into domain XYZ.COM and have ADUC up. I can connect to domain ABC.COM and XYZ.COM, but when I call up a group I need in ABC.COM I cannot see the user I need in XYZ.COM. It is like I need to be at the FORREST level not the DOMAIN level. I know I am an ENTERPRISE and DOMAIN ADMIN. How can I verify if the proper trust is really built and how can I get up one level higher so I can add users in one domain to a group in the other? We are on FORREST LEVEL 2003
0
Comment
Question by:Thor2923
  • 4
  • 3
  • 2
  • +1
10 Comments
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34917817
Are you trying the add an XYZ user to a group in ABC domain ? What is the group type ?

http://www.shariqsheikh.com/blog/index.php/200909/group-nesting-reference-chart/
0
 
LVL 8

Expert Comment

by:Toxacon
ID: 34917818
If domain A trusts domain B, then you are able to add users from domain B to domain A local groups.
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34917827
As to how to verify the trust :

netdom trustTrustingDomainName/d:TrustedDomainName/verify
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 34917828

If they were previously entirely separate then surely they are two entirely separate forests?

And if that is the case, the only type of group you can add users in the remote domain to is (Domain) Local.

Chris
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34917884
Yup, when trying to make sense of the naming of "scopes" with regards to their nesting restrictions,,,take the scope as in where it can be ACL'd on a resource...the acceptance of different objects from trusted domain is different I try explaining somewhat in my blog.

Domain Local - Can accept trusted users but can only be ACL'd on a local resource.
Global Group - Can be ACL'd on a trusted resource but can't accept users from the trusted domain.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 1

Author Comment

by:Thor2923
ID: 34918695
Yes I verified they are two forests so I guess I am going to be limited to Domain locals.

Couldnt i build a doman local on domain abc then then add the Global groups in need ABC to that local group. Then make the user in XYZ a member of the domain local in ABC?
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34918724
I am sorry I didn't understand "Couldnt i build a doman local on domain abc then then add the Global groups in need ABC to that local group. Then make the user in XYZ a member of the domain local in ABC?"

What is your end goal ?
0
 
LVL 1

Author Comment

by:Thor2923
ID: 34918960
Ok, as of now and all I have learned since this started. We have two domains ABC and XYZ. They were previous companies that merged. I did verify they are two different Forests that are trusted. I was told to pull user "smith" from doman XYZ and set her up in ABC. I first considered the migration tool, but was told the users in XYZ have so much bogus info in them I should start fresh. So I created "smith" in ABC. I now want to add ABC/smith to 3 global groups in XYZ. Then I will log her in and start configuring her applications and make adjustments as needed. So...will it be possible to create a Domain local group "trustgroup" in XYZ, add the 3 global groups in XYZ to it. Then add ABC/smith to "trustgroup" domain local that is in XYZ?...thanks for your patience
0
 
LVL 70

Accepted Solution

by:
Chris Dent earned 500 total points
ID: 34919376
No, sorry. Global groups can belong to Local Groups, but not vice-versa.

You'd have to use a Local group to secure whatever resource, then add either Global groups or foreign security principals (aka ABC users) to that.

I wouldn't turn away from ADMT despite what they've said, it would have made this task a lot easier, even for one user at a time. This is because it can be told to write the SID for the user from XYZ into the SID History in ABC (as part of the migration). Then you can continue to control access using the account XYZ (courtesy of the matching SID / SID History) until you're ready to ditch XYZ entirely (and provided you disable SID filtering on the trust).

It makes the user-end of a migration a truck-load easier as well, ADMT can rewrite the user profile when you migrate a computer.

Chris
0
 
LVL 1

Author Comment

by:Thor2923
ID: 34970510
thanks for all of your help everyone, I will probably go with ADMT.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
GPO not applying to designated group-- Server 2012R2 2 59
AD Activation of KMS Key 6 63
Creating and Connection two new domains 5 79
who removed AD Domain ID 9 26
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now