Re: Group Membership Problem

Tech-Archive recommends: Speed Up your PC by fixing your registry



How would I go about fixing this?

"Ace Fekay [MVP]" wrote:

> In news:320613AF-DF84-4499-A22E-AD79204945AD@xxxxxxxxxxxxx,
> TB <TB@xxxxxxxxxxxxxxxxxxxxxxxxx> made this post, which I then commented
> about below:
> > I am having an issue with one of my domains not receiving updates
> > from the parent domain. Here is my setup:
> >
> > domainA --- DomainB (child)
> > |
> > Domain C (child)
> >
> > Domain A is The parent Windows 2000
> > Domain B is the Child Windows 2000
> > Domain C is the Child Windows 2003 mixed
> >
> > Domain C does not show updated membership info from A, however it
> > does allow access to a resource if I add a name. When I look at a
> > users member of tab it only shows groups of the local domain, not
> > groups from Domain A. Domain B is fine.
> >
> > Please help.
> >
> > thanks
>
> It's not working because of the way the forest was upgraded. The forest root
> DCs must be first upgraded to Win2003 prior to upgrading any child domains.
> Specifically, the machine holding the Domain Name Master and PDC Emulator
> role in the forest root domain must be done first, and this is after adprep
> /forestprep and adprep /domainprep have been run on the forest root domain.
> Then adprep /domainprep must be run on each domain prior to upgrading the
> 2000 DCs in those domains.
>
> This is taken from the link I provided in the bottom of my post:
>
> The following computers must be among the first domain controllers that run
> Windows Server 2003 in the forest in each domain: . The domain naming master
> in the forest so that you can create default DNS program partitions.
> . The primary domain controller of the forest root domain so that the
> enterprise-wide security principals that Windows Server 2003's forestprep
> adds become visible in the ACL editor.
> . The primary domain controller in each non-root domain so that you
> can create new domain-specific Windows 2003 security principals.
>
>
>
> 325379 - How to Upgrade Windows 2000 Domain Controllers to Windows Server
> 2003:
> http://support.microsoft.com/?id=325379
>
>
> Unfortunately, I think you now have your work cut-out for you.
>
> --
> Regards,
> Ace
>
> Please direct all replies ONLY to the Microsoft public newsgroups
> so all can benefit.
>
> This posting is provided "AS-IS" with no warranties or guarantees
> and confers no rights.
>
> Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
> Microsoft Windows MVP - Windows Server - Directory Services
> Infinite Diversities in Infinite Combinations.
> =================================
>
>
>
>
.



Relevant Pages

  • Re: Best strategry when 2 NT domains are involved
    ... "Forest root domain" is the first domain created in a new forest. ... You can upgrade one PDC to a forest root domain ... Restructuring Windows NT 4.0 Domains to an Active Directory Forest ... Migrating Windows NT Server 4.0 Domains to Windows Server 2003 ...
    (microsoft.public.windows.server.migration)
  • Re: Group Membership Problem
    ... > Domain A is The parent Windows 2000 ... DCs must be first upgraded to Win2003 prior to upgrading any child domains. ... /forestprep and adprep /domainprep have been run on the forest root domain. ... Windows Server 2003 in the forest in each domain:. ...
    (microsoft.public.windows.server.active_directory)
  • Re: migrate to 2008 AD
    ... The current AD is windows 2003 ... we have one child domain and one forest root domain. ... Will this process work? ...
    (microsoft.public.windows.server.active_directory)
  • RE: Error 1311 when creating cross-forest trust
    ... Maybe I've posted in the wrong place but don't see Windows 2003 server standard edition forum. ... each one working as forest root domain controller. ... Both sites have referenced the other site in Active Directory Sites and Services, its subnet and site-link. ...
    (microsoft.public.windows.server.sbs)
  • Re: My recent Epiphany about operating systems
    ... In Winblow$, the release & bundling of IE was purposely as crippleware, ... & bug delivery system 2 trap people into constantly 'upgrading'. ... simple comparisson of Windows 95 side-by-side with the final Windows ME & ... AND fast shell that Microsoft has released. ...
    (freebsd-questions)