Re: delegate privileges in another domain in another forest

Not sure what the need is for a Universal Group. This is a forest trust so
they are in seperate forests.

I haven't tried this specific angle but you could try creating a local
domain group and making the members of the other forest members of this
group. Then make this new group part of a restricted group withiin a gpo
and provide that the group is a member of the local admins.

Create Universal Group, make it member of Domain Admins of the domain that
you want to administrate, then make the "others" Domain Admins members of
that U.G.

. Enterprise Admins

. Domain Admins (in the forest root domain)

. Schema Admins

We have two forests with two way external trust enabled and working.

I need to allow our domain admins here to have domain admins privileges
the other domain that is in another forest. Since domain admins is a
group I cannot add groups from other domains...

How should I do this? How can I add domain admins from the foreign domain
to all local admins groups in domain A for all workstations?