Re: Trust relationship issue?



I would use domain local groups within the resource domain and grant these domain local groups access to the resources (All users from both domains in one of these groups to test the effectiveness). Use universal groups from the domain the users belong to and place the universal groups within the domain local groups. Also check to make sure port 1433 is open between the two domains.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.
"Carlos Felipe França da Fonseca" <carlosfelipefranca@xxxxxxxxx> wrote in message news:uKIH1nQZJHA.5196@xxxxxxxxxxxxxxxxxxxxxxx
My problem is related to SQL Server.

Many users are having access denied, even being members of a Windows group which has access to the SQL Server 2000 SP4 instance.
They can access the instance only if I explicitly add a login for each user.
I'm sure that there is no group with Deny Access.

The SQL Server is member of domain A and the groups mentioned and their membership are members of domain B.
I know there is an external trust relationship between A and B. Users from A cannot access domain B, but domain B can access resources on domain A.
Logins created for groups from the same domain (A) as the server are working correctly. Only groups from the other domain (B) are not working.
Can it be related to trust relationship?

Does anybody know why it's happening?


.



Relevant Pages

  • Re: Using groups in resources
    ... Group can be used to show totals (by the grouping function), ... Microsoft Project Most Valuable Professional ... I entered some resources grouped them, but I don't see how I ... displayed instead of all its members. ...
    (microsoft.public.project)
  • Re: Cannot Assign Permissions to Domain Local Groups
    ... Domain Local Groups that could be used on domain members came about with Windows 2000 native mode. ... When I try to grant this group permissions on the folder, the group is not searchable; in fact, no domain local groups in the domain are searchable. ... "I created a domain local group in the remote domain and added the requested user accounts as members. ...
    (microsoft.public.windows.server.active_directory)
  • Re: unable to browse domain local groups
    ... provide resources in one forest from another. ... the users domain, then place the global group in the universal group in the ... > domain local groups. ... > The only groups that clients or member server are able to see are domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: cant see domain local groups
    ... contain members from trusted domains (globals cannot). ... Domain Local groups are available in Native mode only since Mixed mode ... won't because the modes (or functional levels) and associated behaviors ...
    (microsoft.public.windows.server.active_directory)
  • Re: Cannot Assign Permissions to Domain Local Groups
    ... users from Domain A as members. ... on the folder, the group is not searchable; in fact, no domain local groups ... "I created a domain local group in the remote domain and added the ...
    (microsoft.public.windows.server.active_directory)

Quantcast