Group memberships incomplete when viewed on different domain



Hi,

We have a Windows 2003 network running in native mode, with an AD
forest containing several domains

A user has an account on Domain A, and is a member of several security
groups, some of which exist in Domain A, some in Domain B.

When I view the properties of this user?s AD account using ADUC on a
server within Domain A (the user?s home domain), the Member Of tab
displays a full list of group memberships for that user.

However, when I view the same user?s account using ADUC on a server
which exists in Domain B, the Member Of tab only displays those groups
which exist in Domain A.

We?re using standard AD replication across all domains, and all the
groups are universal. As I understand it you should be able to view
the full attributes of a users?s AD account using ADUC on any server
in the forest, but this doesn?t seem to be happening in this case. It
is causing a problem because when applications send authentication
queries to AD on domain B, authentication is failing because it
doesn?t recognise that this user is a member of the appropriate
groups.

Any help or ideas on why this might be happening would be appreciated!

Thanks
Anthony

--
Posted using the http://www.windowsforumz.com interface, at author's request
Articles individually checked for conformance to usenet standards
Topic URL: http://www.windowsforumz.com/Active-Directory-Group-memberships-incomplete-viewed-domain-ftopict548105.html
Visit Topic URL to contact author (reg. req'd). Report abuse: http://www.windowsforumz.com/eform.php?p=1733534
.



Relevant Pages

  • Re: Setting a password on an AD account...
    ... I assume it's running in a restricted account right? ... You don't use SSL to bind, and as this runs from a server which is not a domain member (a ... this one fails when the current user is not an administrator on the DC. ...
    (microsoft.public.dotnet.languages.csharp)
  • RE: Bypass Traverse Checking?
    ... Either one will satisfy your needs for your server, and IIS. ... uses the anonymous account IUSR_COMPNAME and is a member of the Guest Group. ... "ACL's" to your IUSR account it should not need this privilege. ...
    (Focus-Microsoft)
  • Re: Windows NT 4.0 BDC Upgrade
    ... >>Microsoft MVP - Windows NT Server ... >>> account ... >>>>> change a member server ... >>>>> upgrade went ...
    (microsoft.public.win2000.active_directory)
  • Re: Users Logging on to Domains
    ... There are some applications that will not run properly unless you are logged on as a member of the domain. ... The OP's problem is that either he or his users think for some reason there is an advantage logging onto a local user account rather than the standard domain account. ... The only local accounts domain member PC's under my control have are, say, where the user takes it home and wants to allow his kids to use it, the user always uses his domain account but local accounts are created for the kids. ... I have several non-domain PC's reporting to and totally under the control of WSUS on my SBS, it's a simple regedit on the PC, no server change required. ...
    (microsoft.public.windows.server.sbs)
  • Re: Unable to open the Web...You are not authorized to perform the current operation
    ... in the event log on restarting the server. ... which uses a network account.) ... site in VS2005 and got the User name/Password authentication pane - I ... tried my ID (which is a member of Administrators on the server) and it ...
    (microsoft.public.dotnet.framework.aspnet)