Re: Access to user properties



Eugen,
as far as I understand, without trust relationship in place, under normal
circumstances, RunAs running on a client computer in one domain will not
allow you to authenticate using a user account from another domain.
However, you could potentially accomplish what you are looking for by
relying on passthrough authentication mechanism. This requires that you
invoke DSA.MSC targeting a domain controller in the other domain while
logged on using an account which name and password are identical to an admin
account in the other domain...

hth
Marcin

"Eugen" <meugen@xxxxxxxxx> wrote in message
news:38B433FC-600E-4F80-8B8F-D3EF046838DB@xxxxxxxxxxxxxxxx
Hello AD Masters,
We have 2 forests with NO trusts between them. When we want to access
properties of users from the other forest through DSA.MSC(ADUC console)
everything works fine, the problem is that we cannot change the passwords
of
those users.
So, my question is would it be possible to change the password of the
isers
from the other forest using ADUC console or other tools?
We use this command line to start DSA.msc: runas /netonly
/user:domain\userid "mmc dsa.msc /server=dc.domain.otherforest

Many thanks


.



Relevant Pages

  • Re: Separating trusted domains
    ... can't make the assumption they aren't in the same forest. ... I've got a question about removing a trust relationship between two ... I removed the trust relationship between the two domains in AD Domains ... homedomain.com site and cease replication, I got a message saying that ...
    (microsoft.public.win2000.active_directory)
  • Re: How trusts work in Windows 2000
    ... > to belong to the same forest to establish a trust relationship ?? ... Can you ping hosts by fqdn? ...
    (microsoft.public.win2000.networking)
  • RE: ADMT v2 Error while migrating a computer
    ... "Jason Tan " wrote: ... > domain and use the AD account? ... You may have to login AD ... > How to Build and Reset a Trust Relationship from a Command Line ...
    (microsoft.public.windows.server.migration)
  • Re: Top Forest controller for existing multiple Forest.
    ... He listed all advantages of a complete forest with multiple domains for each location and Florian used the option to separate all domains into single forests with trusts between the needed ones only, ... Basically you can not have a 'root' where you can connect all Asia forests to and then connect this one to Europe 'root', ... want to make a trust relationship with Europe and Asia, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forest level two way transitive trust
    ... You could potentially establish trust relationship without full connectivity ... A now wants to setup a two way transitive trust relationship with forest ... Example forest A would open up the neccessary ports that are ...
    (microsoft.public.windows.server.active_directory)

Quantcast