Re: sub domain

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Cary Shultz [A.D. MVP] (cwshultz_at_mvps.org)
Date: 09/04/04


Date: Fri, 3 Sep 2004 21:30:04 -0400

James,

I think that Curt would benefit from ADMT v2?

Cary

<jabrandt@online.microsoft.com> wrote in message
news:e5C3eRFkEHA.2788@tk2msftngp13.phx.gbl...
> Each domain will manage have its own set of user accounts. For example
you
> cannot create a Bob account in the root domain then logon to a child
domain
> with the Bob account because ChildDomain\Bob does not exist. You could
use
> RootDomain\Bob to access resources in the child domain with appropriate
> permissions.
> What are you trying to accomplish by having users login to 2 domains?
> If you want the user to authenticate to a DC in the child domain they will
> need an account, or as Laura said, use groups to provide the permissions
via
> groups.
>
> --
> James Brandt [MSFT]
>
>
> "Curt Shaffer" <curt@chilitech.net> wrote in message
> news:ch4p2r01mt7@enews3.newsguy.com...
> >I figured that but I need authentication on the subdomain, do I add a
> >second set of users on the subdomain?
> >
> > Thanks
> >
> > "Laura E. Hunter (MVP)" <hunter(nospamplease)@sfs.upenn.edu> wrote in
> > message news:ufP6%23ODkEHA.3476@tk2msftngp13.phx.gbl...
> >> In a Windows 2000 network, parent and child domains have an automatic
> >> two-way trust relationship between them, so you can assign permissions
to
> >> resources in both domains using the user accounts in each.
> >>
> >> As a best practice, you'll create a global group in each domain
> >> containing the users FROM that domain, then add both global groups to a
> >> Domain Local group in the domain containing the resource they need
access
> >> to. Finally, assign permissions to the Domain Local group. This
creates
> >> the most flexibility and easy maintenance as users move in and out of
> >> different roles and groups.
> >>
> >>
> >>
> >> --
> >> ******************************
> >> Laura E. Hunter - MCSE, MCT, MVP
> >> Replies to newsgroup only
> >>
> >>
> >> "Curt Shaffer" <curt@chilitech.net> wrote in message
> >> news:ch4k8c11hif@enews3.newsguy.com...
> >>>I have just created a subdomain for our network. I don't want to have
to
> >>>recreate the users on the subdomain. I was going to create groups on
the
> >>>subdomain and add the users from the parent to that domain. Is this the
> >>>best way to accomplish this? Thanks for the help
> >>>
> >>> Curt
> >>>
> >>
> >>
> >
> >
>
>



Relevant Pages

  • Re: User login between domains in the same tree/frrest
    ... it would work the other way around too: move your workstation to the SG domain and try to log on with the rogerrabbit account and it should work. ... can a user from a parent domain not login to the child domain because he is ...
    (microsoft.public.windows.server.active_directory)
  • Re: User login between domains in the same tree/frrest
    ... You always log on to the domain your account is in, so if your account ir in domain.local you only can log on to that domain, on the other hand, your MACHINE workstation does not have to be in the same domain, so if you create an account: jessicarabbit in the SG domain, and try to log on with this account, you should be able to do so. ... can a user from a parent domain not login to the child domain because he is ...
    (microsoft.public.windows.server.active_directory)
  • Re: Troubleshooting KDC Event 11
    ... child domain. ... functional level is Windows 2003 Server. ... CHILDDC computer account (apparently a 2nd computer account for the ...
    (microsoft.public.windows.server.active_directory)
  • Re: User login between domains in the same tree/frrest
    ... By default UPN suffix for a user account is the domain containing the ... Is there no way that a user from singapore (child domain) can log onto our ... can a user from a parent domain not login to the child domain because ...
    (microsoft.public.windows.server.active_directory)
  • Re: sub domain
    ... cannot create a Bob account in the root domain then logon to a child domain ... need an account, or as Laura said, use groups to provide the permissions via ... >second set of users on the subdomain? ...
    (microsoft.public.win2000.active_directory)