Re: Forest-Issues

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



The following articles should have all of the relevant information for you. In short, the Domain Admins group is a "Global" group. Global groups can only contain members of its own domain, but can be assigned anywhere in the forest (or trust). Conversely, a domain local group can contain members of any domain, but can only assigned permission in its own domain. As a side note, take a look at the last kb article for information about using the Object Picker when browsing for users. Make sure you are doing your administration from a Windows Server 2003 and up machine.

http://technet2.microsoft.com/windowsserver/en/library/79d93e46-ecab-4165-8001-7adc3c9f804e1033.mspx?mfr=true
http://technet2.microsoft.com/windowsserver/en/library/517b4fa4-5266-419c-9791-6fb56fabb85e1033.mspx?mfr=true
http://support.microsoft.com/kb/878452

--
Joseph T. Corey MCSE, Security+
Systems Administrator
jcorey@xxxxxxx


"Steven L Chan" <StevenLChan@xxxxxxxxx> wrote in message news:3A33AE98-8EEB-48CB-921E-0947BEDACD34@xxxxxxxxxxxxxxxx
Hi,

We created 2 seperate Forest (HQ + Retail) with a 2-way trust between them, also included Forest-Wide authentication.

We are running into an issue that we can not add users/group from one forest into the security group of the second forest. For example: HQ - Active Directory Users and Computers - Domain Admins - Add Members - I only see the HQ domain/forest, but not the Retail domain/forest.

I have never dealt with a Forest-Trust before and I am hoping someone would shed some light, as to if this is possible or not.

Thanks,
Steven

.



Relevant Pages

  • RE: restricted groups?
    ... > transitive trust relationship between all domain in the forest, ... >> impression that you create a Universal Group and add the Domain Admins from ... >> A global group can contain other global groups and accounts from the same ...
    (microsoft.public.windows.server.active_directory)
  • RE: Active Directory network security
    ... >Subject: RE: Active Directory network security ... >X-Mailer: Microsoft Outlook, Build 10.0.2627 ... In fact the only true security boundary in AD is a forest. ... >Domain Admins must be fully trusted. ...
    (Focus-Microsoft)
  • Re: Domain Admins rights....
    ... > Do you have reference to any documentation on this subject? ... It's not that well documented as it's a security hole;-) I'm ... > By "DC's" I am assuming your are referencing the Forest level DC's? ... One fear they have in sense of control is Domain Admins and their ability to ...
    (microsoft.public.windows.server.active_directory)
  • Re: delegate privileges in another domain in another forest
    ... This is a forest trust so ... domain group and making the members of the other forest members of this ... make it member of Domain Admins of the domain that ... you want to administrate, then make the "others" Domain Admins members of ...
    (microsoft.public.windows.server.active_directory)
  • Re: Role based permissions
    ... You may want to look at the Active Directory Delegation whitepaper. ... The DAs should be a single group for the entire forest who are responsible for the core functioning of the entire forest - i.e. ... Joe Richards Microsoft MVP Windows Server Directory Services ... Our sys admins have been assigning way too many people the Domain Admins group and we need to create a more sane subset of role based administrative groups. ...
    (microsoft.public.windows.server.active_directory)