Re: Question: Sharing resources between Forests



Those are your options. Users rarely like anything that they're not used
to... you just have to accept that :-)
The choice of which one you pick is yours. My preference is to create a one
way Trust relationship between the two domains, this way the administration
and management of accounts is easier. But pick the one that fits your
administrative, security and structural needs.

-Allen Firouz


"kelly" wrote:

Thanks! You guys are way to smart. Let me ask you this...the alternatives I
offered were as follows:

1. Use the desktop icon that we have created (it is simply a shortcut to the
recource) and have your users logon with their given domain A credentials.
2. Create a trust between our respective networks.
3. Create local accounts on the server for the users needing access.
4. Bring your domain into our AD forest.

Are these fair alternatives? Would local user accounts on the server allow
them to
seamlessly access the resource? There biggest issue seems to be that they do
not like authenticating with their domain A credentials.
"Herb Martin" wrote:

"kelly" <kelly@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F30F4681-484B-43CF-9106-70B03859A65A@xxxxxxxxxxxxxxxx
We have two networks, each contained within it's own forest, both running
Windows 2003 Server AD. The two networks are connected. We have a
directory
on network A that users on network B need access to. We have created
accounts
on network A for network B users.

So they have separate accounts? Then no trusts are necessary.

Currently we have been having them create a
shortcut to the shared resource and they authenticate using their network
A
credentials.

Perfectly reasonable if you users can deal with having two
separate logons (and passwords.)ou

Question: If network B users map a drive to the shared resource on network
A, check off "Reconnect at Logon", and "Connect using a.." option ( with
their network A crednetials) should the drive get mapped the next time the
machine is restarted? They are complaining that the drive failed to get
re-mapped.

Generally they will have to supply the password again since it is
totally unrelated to their current logon & password.

You might try a (logon) batch file that explicitly sets it up like this:

net use DRIVE: \\ServerName\ShareName * /user:DomainA\UseronDomainA

Change "DRIVE:" to '*' or the drive letter they prefer. The '*' after
the sharepoint is to request a prompt for the password.

Your other (perhaps better) choice is to setup a trust from B to
A and let the users access the files with a single logon.


--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]



.



Relevant Pages

  • Re: Windows 2000 users accounts get locked out
    ... You say that those machines are on your network or not?? ... The caller machine is the name of the machine that ... the user was attempting to logon from at the time of the lockout. ... Still my accounts get locked out. ...
    (microsoft.public.win2000.security)
  • Re: Maximum password Age, Domain Security Policy
    ... with the user command to search for and force accounts with certain password ... ages to change their password at next logon. ... > network drive mappings, while they are working. ... The password expires dialog-box warning is working ...
    (microsoft.public.win2000.group_policy)
  • Re: AD Trust Breaks - object found same name as domain. Help Pleas
    ... The only error reported was when there appeared to be a Network issue. ... There are currently no logon servers available to service the logon request. ... This was when I realised the trust was playing up! ... new Desktops have been appearing on the domain as "acrobat" as the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Auto Logon to network
    ... see a prompt for a name and password when you connect to a network ... > unique ID and password to logon to XP and matching user accounts ... > second screen to logon to network. ... >>all accounts are stored on the domain controllers, or you will have to go ...
    (microsoft.public.win2000.networking)
  • Re: OWA 2003 is only accessable during workingdays
    ... Is it the same when you log in from a client on the network? ... thinking of AD Users and Computers, Properties, Accounts, Logon Hours. ...
    (microsoft.public.exchange.misc)

Loading