Re: issue with Child and Parent Domains



> Thanks Again Paul!!!!, Do you have a document with this explicitly
> defined:

No problem and no, I don't. Although it's on MS' website somewhere...


> You do mean logon from a client to a CD where that client account only
> exists on PD and NOT logging onto the CD server itself? or BOTH?

I mean that unless you have an account in the CD, then you cannot actually
logon to that domain. You can, however, logon to the PD on a computer that
is a member of the CD --in this instance, the authentication is referred to
the other domain. The CD trusts the authentication mechanism in the PD, so
this users is then able to access resources in the CD.


> This is exactly what the department is trying to do but I am was telling
> them that it is not possible.

Correct then.


> Is there such a thing as pass through authentication where users can logon
> to CD, which are currently on the PD? If not, how can you make GPO and
> other functions work on members who are part of the CD.

There's no pass through in that respect. See above for more info. on a
similar scenario.

You can link GPOs that exist in the parent domain to container objects in
the child domain --no problem.


> If i join a computer to the CD and just logon to parent will that user
> still be part of CD. That is will GPO still be able to work?. If so, I
> assume I have to designate the DNS entry on client to that of the CD and
> not of the PD.

No the computer will be a member of the child and the user the PD. GPO will
work on the user account if the user is within scope of a GPO in his or her
domain; computer policy will apply to the computer when it boots --it will
pull from any GPO for which it is within scope -this will be the default
(child) policy, for example.

don't follow you. If you have your user accounts in the domain PARENT and
> you have a child domain CHILD, and you wish to logon to the PARENT domain
> using computers that are members of the CHILD domain this is fine -you
> just
> choose the PARENT domain from the domain: drop-down list at the Winlogon
> screen (Ctrl+Alt+Del

> At this point you are saying that i do not need any groups, but how can
> you assign folder permissions and other resources particular to the CD?

You assign permissions through groups yes. If you have resources in the
child, and user accounts in the parent, you should apply permissions to
(child) domain local groups, and then add parent domain global groups to the
child domain local groups. You then add the users into the global group.
You should do this for the child to.

This looks like so:

Resource/ Permissions -- Domain Local Group -- Global groups (from both
domains)


--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net



.



Relevant Pages

  • Re: GP Based on Machine and User.
    ... Where you currently have one OU with all four computers in it, create four child OUs and move one computer into each OU. ... create four GPOs, one for each set of drives you want to block and link each GPO to the corresponding OU ... OU for User Accounts - put all user accounts in this OU or child OUs ... link the GPO that blocks the drives pertinent to type 1 ...
    (microsoft.public.windows.group_policy)
  • Re: 1 parent and 2 child domains in to 1 main domain
    ... > I currently have one parent domain running mixed mode and 2 child ... > with one domain controller on each domain, ... > having any NT 4.0 bdc's in the parent domain and I want to use admt to ... Then you should have DCs for the domain ...
    (microsoft.public.windows.server.active_directory)
  • RE: Automating Local Computer Admin Rights
    ... to my understanding if you link a GPO to a child OU and not the parent OU the ... create a parent OU and a couple of childs. ... members of the administrators group on the local machine. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Changing Child domain from mixed to native mode
    ... > breaks in parent domain if a child domain is native mode ... The switch to native mode from mixed mode ONLY affects replication between ... DCs, member servers, clients in trusted Win 2k or NT 4.0 domains ... > The parent domain still has a NT 4 bdc. ...
    (microsoft.public.win2000.active_directory)
  • Re: issue with Child and Parent Domains
    ... You require an account in CHILD to logon to CHILD ... If i join a computer to the CD and just logon to parent will ...
    (microsoft.public.windows.server.active_directory)

Loading