Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


Sharepoint 2007 in a newly merged organization

Posted on 2013-10-22
Medium Priority
Last Modified: 2013-10-23
We have just merged with another company. We have a Two-Way Forest trust established successfully between us, Domain A and them, Domain B. We are trying to give users in Domain B access to Sharepoint.  

The issue is that users from Domain B are being challenged for a username and password when connecting to a site on Sharepoint at Domain A.     Once they login, there are little anomalies  that have to do with permission (see description below).   We, Domain A, are a Windows 2003 domain with Sharepoint 2007 running.  Domain B, is a Windows 2008R2 domain running at Windows 2003 functional level.

 In Sharepoint we have gone into Shared Services Administration> User Profiles and Properties>View Import Connections and created a new connection to Domain B's Active Directory.  The Domain B's users now appear in View User Profiles.

Besides being challenged for the un/pw, when they get to the site, the little attachement paperclip icon does not appear, replaced with a generic red X as if the folder permissions in IIS are not correct (the clip is in _images folder).

Any advice on what we have done wrong or left out would be appreciated.  Talk slowly, we aren't Sharepoint people.
Question by:Dgreenbaum
  • 5
  • 2
LVL 44

Expert Comment

by:Rainer Jeschor
ID: 39593391
for the username/password prompt. Can you verify if the SharePoint url is added to the "Local Intranet Zone" of the users of domain B?
You could verify this by letting a user of domain B just open the SharePoint site. IE should show in the bottom status bar its zone (for IE>=8 - for IE>8 its under menu "File" -> "Properties").
By default IE sends the current credentials only to sites listed in the local intranet zone - not in the Trusted sites zone. But please remember - depending on the IT configurations it might be that they are using Group Policies to push IE configurations and can even block changes on the client side.

For the image issue - you should never directly change anything in IIS manager because this can cause issues afterwards as SharePoints internal config could now be out of sync.

The question is, why does it show the red X: due to a 404 not found or due to a 401 permission denied. To track that you might use either a proxy tool like Fiddler or use IE built-in dev tools (shortcut is F12). You will find a tab "Network", then "Start capturing" and now open the page. Images are normally stored under "_layouts/images" (but thats my local SP2010 - I would have to verify this afternoon when I have access to a running MOSS 2007 instance).


Author Comment

ID: 39594443
Hi Rainier... I wil pursue your suggestions and report back.   Thanks so much.


Author Comment

ID: 39594879

I'm excited to say adding the site to the Intranet worked!

regarding the apparent broken link, on the iIE Dev tools page I found no Network tab.  We are still on IE8.  Is that only available in later versions?
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.


Author Comment

ID: 39594883
I neglected to say that our domains are connected through a point to point IpSec tunnel.
LVL 44

Accepted Solution

Rainer Jeschor earned 2000 total points
ID: 39595473
OK so logon issue solved.
I have no IE8 at hand to verify but it could be that this tab was introduced in a newer version of IE.

When you right click on the image and then properties - what address/url is shown?
What happens if you copy this url and paste it to a new browser tab/window?
Could you perhaps post this url here?


Author Comment

ID: 39596420
Hi Rainier.  I got it to work!   Your suggestion to copy the url was exactly the clue I needed.

When I saw it I knew the problem.   In our two way forest trust we have not yet created a forward lookup zone in dns in each other's domains.  The Sharepoint site was being accessed from Domain B with the FQDN:  http://sharepointserver.domainA.local/website/default.aspx.  

That worked for the Sharepoint site but the .gif in question, once they got to the site, was just  http://sharepointserver/website/_layouts/images/attach.gif; no FQDN.

I created a A record in DNS on Domain B to point to Sharepointserver.   The little attachment paper clip .gif could then be found with just the Sharepointserver name.

Thanks for the guidance,

Author Closing Comment

ID: 39596421
Once Rainier heard the whole story he knew just where to look for the answer.  With his help it was clear as a bell.

Featured Post

Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When using a search centre, I'm going to show you how to configure Sharepoint's search to only return results from the current site collection. Very useful when using Office 365 with multiple site collections.
A while back, I ran into a situation where I was trying to use the calculated columns feature in SharePoint 2013 to do some simple math using values in two lists. Between certain data types not being accessible, and also with trying to make a one to…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

579 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question