Solved

Active Directory Trust permissions

Posted on 2014-03-05
7
323 Views
Last Modified: 2014-03-26
I have created a trust between two domains and I am now trying to share security groups but can only see from each domain the OU Builtin what permissions needs to be added to the other OU's so i can see them between the domains?

Thanks
0
Comment
Question by:Dan130
  • 2
7 Comments
 
LVL 19

Expert Comment

by:helpfinder
ID: 39906052
check this:
[link removed]

what kind of trust relationship did you do?
what is the domain functional level of each domain?
are the domains in the same forest?
0
 
LVL 1

Author Comment

by:Dan130
ID: 39906059
what kind of trust relationship did you do?
what is the domain functional level of each domain? server 2003
are the domains in the same forest?

Trust Type: forest transitive: Yes
0
 
LVL 1

Author Comment

by:Dan130
ID: 39906310
Looking at the link you sent me its telling me to use domain local groups instead which is fine going forward but what about adding users to existing AD groups that's are not domain local.
0
 
LVL 35

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39912357
In both domains under built-in container double click administrators group and add domain admins group of opposite domain there vice versa

This will enable view of entire OU structure of both domains vice versa

Also you cannot add users from one domain to global group in another domain
Global groups can contains users from its own domain only

If you wanted to add users from one domain to another, then you have two ways

Add global group in one domain to universal group in another domain
OR
add global group in one domain to domain local group in another domain

Also in another domain resource access then need to be routed through universal groups or domain local groups

Mahesh
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
HP DL160 G6 Hard Disk Question 3 42
Radius Debug Error 16 55
active directory 5 49
PowerShell:  Add Header to Out-File 2 23
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now