Upgrade Win2K AD to Native Mode, File sharing problem



I have a file server which was a domain controller running on Win2k Mixed
mode. I followed the convention of my company IT department to set ACLs on
the share files by:
1. put all the authenticated users to a Globle Group
2. put the Globle Group into a Domain Local Group
3. Files/Folders ACLs are assigned by only using these Domain Local Groups.

Before I upgraded the Domain to Win2k native mode, users didn't have any
problem in retriving data from the server.

When I changed the AD mode, users compaining about that they got problem
accesing files they have the proper right. Error message is 'Access denied,
you don't have proper access right...' But I check the Domain Local Group,
the user is listed in the group. What I have to do is to delete the user
from the Domain Local Group, then add the same user in it. On the users PC,
refresh group policy, restart the pc, most of the users are able to use the
resources on the Server, but some of them still have the same problem.

Now what I have to do is to add Globle Group to the files/folders ACL, this
method solves my proble, but it offends the Company IT convention.

What shall I do?


.



Relevant Pages

  • RE: how to add NT domain local group security on win2000
    ... My name is Joe Wu, and it is my pleasure to work ... |I upgrade the "NT FILE SERVER" to another powerful Machince with WIN2000 OS ... |I use the "Scopy" to copy all the security right from the old "NT FILE ... |All the files security right are assigned using the NT Domain Local Group. ...
    (microsoft.public.windows.server.migration)
  • RE: Local groups migration
    ... local SAM database of the member server the users are denied access. ... In cases where the Domain Local Group had more than one Global Group as ... No domain migration ever occurred, no protar.mdb existed, it does not ...
    (microsoft.public.windows.server.migration)
  • RE: question on using migration tool and user groups
    ... member on the right, separated by a comma. ... In cases where the Domain Local Group had more than one Global Group as ... We installed ADMTv2 on the W2K3 member server holding the migrated data ... >>to the folder, I created a salesman group, gave it full rights to the ...
    (microsoft.public.windows.server.migration)
  • Re: External trust & resources sharing
    ... I think the problem is in SQL 2000 server. ... not possible to grant permissions to the domain local group on the database ... this sounds like you're not in native mode. ...
    (microsoft.public.windows.server.active_directory)
  • Re: question on using migration tool and user groups
    ... but I thought the point of the migration too was that you didnt have to do ... If the windows 2003 server is on the domain, why does it not recognize the ... To correct this we used Addusers.exe from the Windows 2000 Resource Kit ... > 1:1 mapping of Domain Local Group friendly names on the right, ...
    (microsoft.public.windows.server.migration)

Loading