RE: Trust Relationship Between 2 Domains



Hi Vincent

Thank you for your reply, but I have already tried to reset the account and
this has not worked. Isn't there another way as by resetting the account I
will need to rejoin the PC to the domain. How can I achieve this on the
Domain controllers?

Thank you Imran

"Vincent Xu [MSFT]" wrote:

Hi,

Actually, I suggest you to reset computer account.

320187 HOW TO: Manage Computer Accounts in Active Directory in Windows 2000
http://support.microsoft.com/default.aspx?scid=kb;EN-US;320187


Best regards,

Vincent Xu
Microsoft Online Partner Support

======================================================

Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================



--------------------
Thread-Topic: Trust Relationship Between 2 Domains
thread-index: AcZ00yQ6Z9ZuhuDNTkSIrmTrBOYw3Q==
X-WBNR-Posting-Host: 217.158.191.82
From: =?Utf-8?B?QmFyYXppIEZ1ZW50ZQ==?=
<BaraziFuente@xxxxxxxxxxxxxxxxxxxxxxxxx>
References: <D9CC0B92-3132-4637-8FAD-E22D30CA1E03@xxxxxxxxxxxxx>
<WTdSqrKdGHA.5024@xxxxxxxxxxxxxxxxxxxxx>
Subject: RE: Trust Relationship Between 2 Domains
Date: Thu, 11 May 2006 01:16:02 -0700
Lines: 153
Message-ID: <EAB52A09-1480-4478-9B39-E783AF528F95@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.windows.server.migration
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.windows.server.migration:23677
NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.windows.server.migration

Hi Vincent

Thank you for your reply, but the problem is not with just one PC but
several, i.e. 500 workstations and 18 servers, how could I possibly reset
the
computer accounts and rejoin the domain on Domain Controllers, Exchange
Servers, DNS Servers etc. Isn't there another way or at least a method
in
which I can update all the PC's automatically, without having the need to
rejoin the PC's one by one.

Thank you

Barazi

"Vincent Xu [MSFT]" wrote:

Hi,

It appears to be the computer account corrupt. You can try to reset the
computer account.

To perform this procedure, you must be a member of the Account
Operators
group, the Domain Admins group, or the Enterprise Admins group in
Active
Directory, or you must have been delegated the appropriate authority.
As a
security best practice, consider using Run as to perform this
procedure. 1.
Click Start , point to Programs , point to Administrative Tools , and
then
click Active Directory Users and Computers .
2. In the console tree, under the domain node, click Computers , or
click
the folder in which the computer is located.
3. In the details pane, right-click the computer, and then click Reset
Account . NOTE : Resetting a computer account breaks that computer's
connection to the domain and requires it to rejoin the domain.
To reset a computer account using a command line, type the following at
a
command prompt, and then press ENTER
dsmod computer ComputerDN -reset

320187 HOW TO: Manage Computer Accounts in Active Directory in Windows
2000
http://support.microsoft.com/default.aspx?scid=kb;EN-US;320187


Best regards,

Vincent Xu
Microsoft Online Partner Support

======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader
so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no
rights.
======================================================



--------------------
Thread-Topic: Trust Relationship Between 2 Domains
thread-index: AcZ0JBlvZegG2m8DRdyFQa81IRPgGA==
X-WBNR-Posting-Host: 217.158.191.82
From: =?Utf-8?B?QmFyYXppIEZ1ZW50ZQ==?= <Barazi
Fuente@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: Trust Relationship Between 2 Domains
Date: Wed, 10 May 2006 04:23:02 -0700
Lines: 54
Message-ID: <D9CC0B92-3132-4637-8FAD-E22D30CA1E03@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.windows.server.migration
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.windows.server.migration:23661
NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.windows.server.migration

Hello

BACKGROUND
We have 2 domains setup at the site. Domain A was upgraded from NT to
AD
2003 and Domain B at the time remained as NT. A trust relationship
was
setup
between the 2 domains for users to access resources from Domain A &
B.
This
has been working very well.

Domain B was then migrated to AD 2003 also. The server was upgraded
to be
part of the Forest of Domain A. In the Forest is Domain A & Domain B.

Seeing
Domain B was upgraded, the trust relationships were inherited as:

TRUST TYPE: Tree Root
TRANSITIVE: Yes
Incoming and Outgoing in Domain A and Domain B.

All the security and Share permissions were set in Domain A & B so
users
from both domains have access.

PROBLEMS
The first problems I noticed was that the DNS servers in Domain A did
not
contain all the server details of Domain B, however I could see all
the
DNS
servers of Domain B in Domain B. I checked all the replication
topology.
Everything is being replicated without any errors to all servers in
the
Forest.

What I found strange was that users in Domain B could access
resources in
Domain A without any problems, however users in Domain A could not
access
any
resources in Domain B. A dialog box would always appear asking the
user
to
put in a username and password. Even though the user puts in the
Domain
Admin username and password of Domain B, the user still gets Access
is
Denied. The user account works perfectly fine when logging onto any
servers
and workstations in Domain B.

Recently I found 1 user in Domain A who could access resources
successfully
to domains A & B. After being unsuccessful in finding any
differences
with
his PC and problem PC's as the issue was with the computer not user
account.

TEMPRORARY SOLUTION
I decided to re-join a problem PC back into Domain A and this
resolves
the
problem. The computer can successfully browse resources in both
domains
regarding the correct security permissions have been set.

WHAT SHOULD I DO?
Unfortunately I cannot rejoin all the workstations from Domain A as
the
problem is also with the servers, including DC's, DNS, WINS, EXCHANGE
etc...
There has got to be another way. Why do I have to rejoin the PC's
for
them
to work. Is there another way I can achieve my goal. I'm sure all
the
DNS
entries will appear once this is done. Can you please help?

Thank you

Barazi







.



Relevant Pages

  • Re: Rejoin Computer a/c to Domain?
    ... to 'reset account'? ... >objects) and select a computer account object, ... click and select reset ... >> connection to the domain and requires it to rejoin the ...
    (microsoft.public.win2000.active_directory)
  • Re: reset computer account / Restore
    ... Okay sorry I didn't understand it was reset. ... > This is a computer account not a user account:\ Also the account is not ... we just reset the computer account from the active directory ... > If possible we shouldn't restore active directory from scratch, ...
    (microsoft.public.win2000.active_directory)
  • Re: Random "computer account was not found" broken profiles Server
    ... It could be connectivity, DNS, computer account password, secure ... Speaking of connectivity, "ping" alone doesn't count. ... Make sure that your clients use only their local DNS Server. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Quick question on resetting computer accounts in AD
    ... SBS Server Management console does not have "Reset Account" command to ... In fact, the SBS Server Management console has already integrated ADUC, you ... Right click the computer account in right pane, ...
    (microsoft.public.windows.server.sbs)
  • Re: what is reset account?
    ... The reset account resets the password to the default password if you need to rejoin a machine to the domain. ... account WITHOUT "rejoining" it to the domain. ... Reset avoids recreating and rejoining a computer account to ...
    (microsoft.public.win2000.active_directory)