Re: Multiple Domains




"EMan" <EMan@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8F17E774-57C2-41B7-90ED-F708DAAA136D@xxxxxxxxxxxxxxxx
I have two Domains D1 and D2 where there is a one way trust between D1 and
D2
(D1 trusts D2).

Then users in D2 can (be granted) access (to) resources in D1.

I have an application using LDAP to read the AD in D2 from
D1 using a service account from D2.

Ok.

The service account is a user in the OU I am trying to read.

Doesn't matter. Membership in any particular OU has nothing to
do with access, except in the sense that you have chosen to delegate
there.

When the LDAP is executed I get some users, but not all
of the users and I can't understand the reason why all users are not
returned. What can I do to read all of the users?

Chances are the same results will be returned if you execute this as
any other user (e.g., and Admin) would get the same results -- IF
not then you likely have a permission problem where you have not
delegated the necessary permissions to the account.

Check you script locally, check it using another (admin) user, check
it remote with the admin until you can figure out what the specific
difference is if you have incorrect results.

Thanks,
EMan


--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)


.



Relevant Pages

  • Re: Multiple Domains
    ... D1 using a service account from D2. ... except in the sense that you have chosen to delegate ... not then you likely have a permission problem where you have not ... Check you script locally, check it using another (admin) user, check ...
    (microsoft.public.windows.server.active_directory)
  • Re: Multiple Domains
    ... a default number of results that it returns in a query. ... (e.g., admin etc) ... except in the sense that you have chosen to delegate ... not then you likely have a permission problem where you have not ...
    (microsoft.public.windows.server.active_directory)
  • Server Hangs then locks!
    ... Set up a service account that has admin privileges ... and add the exchange admin group to it and set the services to start ... dozen exchange services starting with an account that has admin ...
    (microsoft.public.windows.server.sbs)
  • Re: Installing a Secondary Site Fails
    ... SMS can't resolve the name. ... Are you in advanced or standard security? ... a cmd prompt under the context of the SMS Service account. ... >> to grant it admin rights on secondary site server: ...
    (microsoft.public.sms.setup)
  • Re: Password management policy when an admin left the company ?
    ... If not i think you have to check any server which service account is used. ... several admin and services accounts stored ... As he had access to the protected file containing every passwords, ...
    (microsoft.public.windows.server.security)