Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

adding user in one domain to a group in a different domain in AD

Posted on 2011-02-17
10
Medium Priority
?
703 Views
Last Modified: 2012-05-11
We have two domains that were previously two different companies. I have been told by level 3 engineering that "a sufficient trust has been built". I was asked to put a user in what I will call domain ABC.COM into a group in domain XYZ.COM. I am logged into my workstation into domain XYZ.COM and have ADUC up. I can connect to domain ABC.COM and XYZ.COM, but when I call up a group I need in ABC.COM I cannot see the user I need in XYZ.COM. It is like I need to be at the FORREST level not the DOMAIN level. I know I am an ENTERPRISE and DOMAIN ADMIN. How can I verify if the proper trust is really built and how can I get up one level higher so I can add users in one domain to a group in the other? We are on FORREST LEVEL 2003
0
Comment
Question by:Thor2923
  • 4
  • 3
  • 2
  • +1
10 Comments
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34917817
Are you trying the add an XYZ user to a group in ABC domain ? What is the group type ?

http://www.shariqsheikh.com/blog/index.php/200909/group-nesting-reference-chart/
0
 
LVL 8

Expert Comment

by:Toxacon
ID: 34917818
If domain A trusts domain B, then you are able to add users from domain B to domain A local groups.
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34917827
As to how to verify the trust :

netdom trustTrustingDomainName/d:TrustedDomainName/verify
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 71

Expert Comment

by:Chris Dent
ID: 34917828

If they were previously entirely separate then surely they are two entirely separate forests?

And if that is the case, the only type of group you can add users in the remote domain to is (Domain) Local.

Chris
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34917884
Yup, when trying to make sense of the naming of "scopes" with regards to their nesting restrictions,,,take the scope as in where it can be ACL'd on a resource...the acceptance of different objects from trusted domain is different I try explaining somewhat in my blog.

Domain Local - Can accept trusted users but can only be ACL'd on a local resource.
Global Group - Can be ACL'd on a trusted resource but can't accept users from the trusted domain.
0
 
LVL 1

Author Comment

by:Thor2923
ID: 34918695
Yes I verified they are two forests so I guess I am going to be limited to Domain locals.

Couldnt i build a doman local on domain abc then then add the Global groups in need ABC to that local group. Then make the user in XYZ a member of the domain local in ABC?
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34918724
I am sorry I didn't understand "Couldnt i build a doman local on domain abc then then add the Global groups in need ABC to that local group. Then make the user in XYZ a member of the domain local in ABC?"

What is your end goal ?
0
 
LVL 1

Author Comment

by:Thor2923
ID: 34918960
Ok, as of now and all I have learned since this started. We have two domains ABC and XYZ. They were previous companies that merged. I did verify they are two different Forests that are trusted. I was told to pull user "smith" from doman XYZ and set her up in ABC. I first considered the migration tool, but was told the users in XYZ have so much bogus info in them I should start fresh. So I created "smith" in ABC. I now want to add ABC/smith to 3 global groups in XYZ. Then I will log her in and start configuring her applications and make adjustments as needed. So...will it be possible to create a Domain local group "trustgroup" in XYZ, add the 3 global groups in XYZ to it. Then add ABC/smith to "trustgroup" domain local that is in XYZ?...thanks for your patience
0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 2000 total points
ID: 34919376
No, sorry. Global groups can belong to Local Groups, but not vice-versa.

You'd have to use a Local group to secure whatever resource, then add either Global groups or foreign security principals (aka ABC users) to that.

I wouldn't turn away from ADMT despite what they've said, it would have made this task a lot easier, even for one user at a time. This is because it can be told to write the SID for the user from XYZ into the SID History in ABC (as part of the migration). Then you can continue to control access using the account XYZ (courtesy of the matching SID / SID History) until you're ready to ditch XYZ entirely (and provided you disable SID filtering on the trust).

It makes the user-end of a migration a truck-load easier as well, ADMT can rewrite the user profile when you migrate a computer.

Chris
0
 
LVL 1

Author Comment

by:Thor2923
ID: 34970510
thanks for all of your help everyone, I will probably go with ADMT.
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question