Re: Child Domain access




Hi

Thanks for your explanation guys.......the fog is clearing now

I was confusing authenticating to the child domain with the ability to
actually manage it. It now makes sense that I cannot authenticate in a domain
where my user account doesnt exist (even if it exists in a parent domain),
however I have all the rights required (with domain/ent admin) to manage it

I am now going away to read about the difference between universal,global and
domain local groups because I dont understand that while viewing the groups
in the child domain I cant add a user account from the parent domain to a
global group whereas I can add the user to a domain local or universal group.

What happens is in ADUC in the child domain I open the Domain admin group,hit
add,change the location from sub.mydomain.local to mydomain.local, input a
user account from mydomain.local and it wont add it to the group. Whereas it
will if I do the same for a domain local group, or for a universal group

Anyway, if you care to let me know why? great !, but you have helped a lot so
far for which I thankyou

Kind regards

Simon


--
Message posted via WinServerKB.com
http://www.winserverkb.com/Uwe/Forums.aspx/windows-server-ad/200507/1
.