Solved

adding user in one domain to a group in a different domain in AD

Posted on 2011-02-17
10
699 Views
Last Modified: 2012-05-11
We have two domains that were previously two different companies. I have been told by level 3 engineering that "a sufficient trust has been built". I was asked to put a user in what I will call domain ABC.COM into a group in domain XYZ.COM. I am logged into my workstation into domain XYZ.COM and have ADUC up. I can connect to domain ABC.COM and XYZ.COM, but when I call up a group I need in ABC.COM I cannot see the user I need in XYZ.COM. It is like I need to be at the FORREST level not the DOMAIN level. I know I am an ENTERPRISE and DOMAIN ADMIN. How can I verify if the proper trust is really built and how can I get up one level higher so I can add users in one domain to a group in the other? We are on FORREST LEVEL 2003
0
Comment
Question by:Thor2923
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +1
10 Comments
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34917817
Are you trying the add an XYZ user to a group in ABC domain ? What is the group type ?

http://www.shariqsheikh.com/blog/index.php/200909/group-nesting-reference-chart/
0
 
LVL 8

Expert Comment

by:Toxacon
ID: 34917818
If domain A trusts domain B, then you are able to add users from domain B to domain A local groups.
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34917827
As to how to verify the trust :

netdom trustTrustingDomainName/d:TrustedDomainName/verify
0
Comparison of Amazon Drive, Google Drive, OneDrive

What is Best for Backup: Amazon Drive, Google Drive or MS OneDrive? In this free whitepaper we look at their performance, pricing, and platform availability to help you decide which cloud drive is right for your situation. Download and read the results of our testing for free!

 
LVL 71

Expert Comment

by:Chris Dent
ID: 34917828

If they were previously entirely separate then surely they are two entirely separate forests?

And if that is the case, the only type of group you can add users in the remote domain to is (Domain) Local.

Chris
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34917884
Yup, when trying to make sense of the naming of "scopes" with regards to their nesting restrictions,,,take the scope as in where it can be ACL'd on a resource...the acceptance of different objects from trusted domain is different I try explaining somewhat in my blog.

Domain Local - Can accept trusted users but can only be ACL'd on a local resource.
Global Group - Can be ACL'd on a trusted resource but can't accept users from the trusted domain.
0
 
LVL 1

Author Comment

by:Thor2923
ID: 34918695
Yes I verified they are two forests so I guess I am going to be limited to Domain locals.

Couldnt i build a doman local on domain abc then then add the Global groups in need ABC to that local group. Then make the user in XYZ a member of the domain local in ABC?
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34918724
I am sorry I didn't understand "Couldnt i build a doman local on domain abc then then add the Global groups in need ABC to that local group. Then make the user in XYZ a member of the domain local in ABC?"

What is your end goal ?
0
 
LVL 1

Author Comment

by:Thor2923
ID: 34918960
Ok, as of now and all I have learned since this started. We have two domains ABC and XYZ. They were previous companies that merged. I did verify they are two different Forests that are trusted. I was told to pull user "smith" from doman XYZ and set her up in ABC. I first considered the migration tool, but was told the users in XYZ have so much bogus info in them I should start fresh. So I created "smith" in ABC. I now want to add ABC/smith to 3 global groups in XYZ. Then I will log her in and start configuring her applications and make adjustments as needed. So...will it be possible to create a Domain local group "trustgroup" in XYZ, add the 3 global groups in XYZ to it. Then add ABC/smith to "trustgroup" domain local that is in XYZ?...thanks for your patience
0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 500 total points
ID: 34919376
No, sorry. Global groups can belong to Local Groups, but not vice-versa.

You'd have to use a Local group to secure whatever resource, then add either Global groups or foreign security principals (aka ABC users) to that.

I wouldn't turn away from ADMT despite what they've said, it would have made this task a lot easier, even for one user at a time. This is because it can be told to write the SID for the user from XYZ into the SID History in ABC (as part of the migration). Then you can continue to control access using the account XYZ (courtesy of the matching SID / SID History) until you're ready to ditch XYZ entirely (and provided you disable SID filtering on the trust).

It makes the user-end of a migration a truck-load easier as well, ADMT can rewrite the user profile when you migrate a computer.

Chris
0
 
LVL 1

Author Comment

by:Thor2923
ID: 34970510
thanks for all of your help everyone, I will probably go with ADMT.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question