Re: Add Users from other domain to Domain Admins group

From: Chriss3 [MVP] (noSpamHere_at_chrisse.se)
Date: 08/18/04


Date: Wed, 18 Aug 2004 18:00:04 +0200

Hello,

Have a look at the Default Groups
http://www.microsoft.com/technet/prodtechnol/windows2000serv/evaluate/featfunc/07w2kadc.mspx

Global Group can't have members from another domain, instead add the users
to the administrator group of the particular domain.

-- 
Regards
Christoffer Andersson
Microsoft MVP - Directory Services
No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips
"Magnus Blomberg" <magnus.blomberg@skanska.se> skrev i meddelandet
news:%23p9AgSThEHA.1344@TK2MSFTNGP11.phx.gbl...
> Hello!
>
> I just added a new resource domain in our large organization.
> I have setup a trust to our NT4 master domain where the users are located.
>
> Now I want to add users from the master domain in the Domain Admins group
of
> my new resource domain.
> This can't be done cause the master domain is not available in the
> "locations tree" for group Domain Admins.
> I created a new local group, and added the users there without any
problems,
> but I can't add this group to the Domain Admins group.
>
> Are there some way to solve this issue?
>
> I also must say, I'm quite new to the concept Active Directory.
>
> Regards Magnus
>
>


Relevant Pages

  • Add Users from other domain to Domain Admins group
    ... I just added a new resource domain in our large organization. ... I have setup a trust to our NT4 master domain where the users are located. ... "locations tree" for group Domain Admins. ... but I can't add this group to the Domain Admins group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Access Denied on GPMC
    ... security on folders and subfolders under sysvol are all assigned to domain ... on the active directory, it still says access denied, i checked on the active ... > Domain Admins FC, especially the \Sysvol share. ...
    (microsoft.public.windows.server.general)
  • Re: Role based permissions
    ... You may want to look at the Active Directory Delegation whitepaper. ... The DAs should be a single group for the entire forest who are responsible for the core functioning of the entire forest - i.e. ... Joe Richards Microsoft MVP Windows Server Directory Services ... Our sys admins have been assigning way too many people the Domain Admins group and we need to create a more sane subset of role based administrative groups. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD permissions
    ... > In my windows 2003 server Active Directory domain I ... > domain admins so they can add computers to domains etc. ... I have looked into delegation of control ... I once had a customer where they had a lot of domain admins and account ...
    (microsoft.public.windows.server.active_directory)
  • Re: Rights and Permissions of Domain Admins group in AD
    ... Domain Admins does have special rights in W2K from what I remember, ... > In a native-mode Active Directory environment, ... > domain controllers and on member servers and workstations? ...
    (microsoft.public.win2000.security)