Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 2596
  • Last Modified:

How to use DSMOD to add user from a different domain to a Distribution List or Security Group

I may be doing something wrong when I try to add a user from another domain in the forest using DSMOD.

This is the syntax I use:
dsquery user forestroot -name "<NAME OF USER>" | dsmod group "DN OF GROUP" -addmbr

When I use that command and the user is in the London domain it works fine, but if I try with a user from, for example, Japan, then it fails with the error: The specified group type is invalid.

This happens for both Security and Distribution groups. And they are, naturally, universal groups.

If I add the users via Active Directory Users & Groups MMC, then I can add them fine.
0
LPetersson
Asked:
LPetersson
  • 4
  • 3
1 Solution
 
Krzysztof PytkoActive Directory EngineerCommented:
You should place global group(s) into universal groups and then add only users to global groups within their domain. DS Tools don't allow for adding members from different domains directly to the groups in other domain(s).

Regards,
Krzysztof
0
 
LPeterssonAuthor Commented:
Really? Damn, that's a shame.

Well, I would prefer to use groups like that, but this client isn't too keen on nested groups except where absolutely necessary.
0
 
Krzysztof PytkoActive Directory EngineerCommented:
OK, that's not true :)
I checked it in my test environment and it works fine :) (you cannot do that for global groups in remote domain because it is not supported)

check this syntax

dsquery user "dc=domain,dc=com" -name "User Name" | dsmod group "cn=groupname,ou=OUlocation,dc=domain2,dc=com" -addmbr

You need for that at least Domain Functional Level at Windows 2003 mode.

Krzysztof
0
Veeam and MySQL: How to Perform Backup & Recovery

MySQL and the MariaDB variant are among the most used databases in Linux environments, and many critical applications support their data on them. Watch this recorded webinar to find out how Veeam Backup & Replication allows you to get consistent backups of MySQL databases.

 
LPeterssonAuthor Commented:
Hmmm, unfortunately that doesn't work for me.

When I use that syntax I still get the error: The specified group type is invalid.

Our domain functional level is indeed Windows 2003 mode.

0
 
Krzysztof PytkoActive Directory EngineerCommented:
Are you sure that you have Universal groups ? Could you post syntax here, please?

Krzysztof
0
 
LPeterssonAuthor Commented:
Yupthey were universal groups and it eventually did work.

Thanks for the help.
0
 
Krzysztof PytkoActive Directory EngineerCommented:
You're welcome :)
0
 
Darius GhassemCommented:
This question has been classified as abandoned and is being closed as part of the Cleanup Program. See my comment at the end of the question for more details.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now