Re: Trouble with admin access after creating trust.



I'm not talking about the local group on the PC. I'm talking about the
domain group called Administrators, which is a local built in group. I
added the domain admins group from the 2003 domain to it (on the 2000
domain) but it wouldn't work.

Weird thing though, come in today and it is working. Nothing has
changed...but I don't see how it would need 2 days to replicate
permissions or whatever it does.


Paul Bergson [MVP-DS] wrote:
You should have local admin access on the local machine, but you won;t have
any special privleges at all in the domain.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

<schmierer2@xxxxxxxxxxxxxxxxxxxxx> wrote in message
news:1162851813.710255.278010@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Thanks Paul. I actually want domain access in the 2000 domain, with an
account from the 2003 domain. I did add my domain 2003 admin account
into the 2000 local administrator group, but when I log on the 2000
domain with that account I don't get admin access.

I can't do what you said though because the domain admin group won't
allow users/groups to be added from another domain, which is why I
needed to add it to the administrators local group.

Cheers,
Owen.


Paul Bergson [MVP-DS] wrote:
You don't by default have admin credentials in this domain, they have to
be
added. Have the admin from the 2000 domain add your 2003 id in to the
domain admins group.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.

<schmierer2@xxxxxxxxxxxxxxxxxxxxx> wrote in message
news:1162772138.516628.315630@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi guys. I'm sure there is something simple that I'm not doing
properly but I'm looking for some help.

I've created a trust (two way) from a 2003 domain to a 2000 domain and
the trust works fine. I can log on the 2000 domain with an account
from my 2003 domain no problem. I have added an admin global group
from the 2003 domain into the local Administrators group on the 2000
domain... my problem is that when I log onto the 2000 domain with an
account from the 2003 domain then I don't have admin access.

Am I doing something wrong?

Thanks very much,
Owen.



.



Relevant Pages

  • RE: Access Denied when using ADMT to migrage Computer Accounts
    ... the Domain Admins group will be added ... to the local Administrators group if the customer joins in the domain. ... Please add the user account to the local ...
    (microsoft.public.windows.server.migration)
  • RE: ADMT never sucesess of migrating computer account :(
    ... The account you use to run ADMT must have enough permission to complete the ... of the local Administrators group on each computer to be migrated. ... Add Win2k3Dom Domain admins group to win2k Domain admins group and ...
    (microsoft.public.windows.server.migration)
  • Re: NT 4.0/Exchange 5.5 to Windows/Exchange 2003
    ... > migration does not require any special domain configuration. ... The account must have permission to create computer ... > of the local Administrators group on each computer to be migrated. ... Add Win2k3Dom Domain admins group to NT Domain admins group and ...
    (microsoft.public.windows.server.migration)
  • Re: need help with Group Policy
    ... Make sure that your user account is in the domain admins group and that the ... domain admins group is in the administrators group for the domain in Active ... Administrators also need full control "share" permissions to the ...
    (microsoft.public.win2000.group_policy)
  • Re: Confused
    ... the members of the Domain Admins group are "administrators" of ... Who do you have in the domain "domain admins" and in the member servers ... I check the domain admins group on a dc in child ...
    (microsoft.public.win2000.active_directory)