Re: Global Group

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Laura E. Hunter \(MVP\) (hunter(nospamplease)_at_sfs.upenn.edu)
Date: 06/30/04


Date: Wed, 30 Jun 2004 13:13:27 -0400

This is by design. Global groups can only contain objects from the same
domain that the group is located in.

If you have a resource in DomainB, and you need to grant access to users in
both DomainA and DomainB, best practices would be to do the following:

Create a global group in DomainA. Add the users from DomainA to this group.

Create a global group in DomainB. Add the users from DomainB to this group.

Create a Domain Local group in DomainA. Add the Global Groups from DomainA
and DomainB to this Domain Local group.

Assign permissions to the resource to the Domain Local group.

http://www.microsoft.com/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/sag_ADgroups_3groupscopes.asp

-- 
******************************
Laura E. Hunter - MCSE, MCT, MVP
Replies to newsgroup only
"tejal" <tejal_5@yahoo.com> wrote in message 
news:2353201c45ec2$7bd3f010$a601280a@phx.gbl...
> HI...
>
> i ahev problem with global group after join child domain..
> i can manage child domain user  from parent domain but i
> have problem when i will add child domain user to parent
> domain global group..and same on either side.means i can
> not add user from parent domain to child domain global
> group...
>
> it is onlt on global gorup all other groups are fine..
>
> if you pls let me know
>
> TEjal 


Relevant Pages

  • Re: Child Domains and GPOs
    ... Herb, That worked. ... I created a global group in the child domain, ... >> of the forest trusts every other. ...
    (microsoft.public.win2000.active_directory)
  • Re: Should be a simple task
    ... Add the Domain Admins global group from the parent domain into the ... Built-in\Administrators local group in the child domain. ... if the users who will be administering the child domain are only a ...
    (microsoft.public.windows.server.active_directory)
  • Re: Should be simple
    ... "Domain Admins" global group in your child domain. ... > What is the easiest way to make selected users from the parent domain into ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to create users that have access to parent and child domain.
    ... both parent and child domain. ... child domain add added an user to that global group from parent domain ... Normally you will place the users in a Global group of their own domain, ... Users already can access resources everywhere in the forest as long as ...
    (microsoft.public.win2000.active_directory)
  • Re: Should be a simple task
    ... The domain admins group is a global group and as ... >> users in the child domain. ... >>> I want to manage the student's accounts in the parent domain but NOT ...
    (microsoft.public.windows.server.active_directory)