RE: Unable to add domain admins from trusted domain to local admin

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Thanks for your help.

I got around the problem by removing the trusts and re-creating them. Not
sure why this caused a problem - maybe there was an issue with DNS at the
time when I created the trust and it never picked up newer info.




"Vincent Xu [MSFT]" wrote:

HI,

Try following command to do a group look up :

netdom trust local domain /domain:trust domain /verify /userd:trust
domain\user /passwordd:*

Type the password associated with the domain user:

Please let me know the entire output.

Thanks.



Best regards,

Vincent Xu
Microsoft Online Partner Support

======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================



--------------------
Thread-Topic: Unable to add domain admins from trusted domain to local
administr
thread-index: AcaO6WxoQqXTHB7yTMGpZ1YKRB2JCA==
X-WBNR-Posting-Host: 134.151.32.204
From: =?Utf-8?B?SnVsaWU=?= <Julie@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: Unable to add domain admins from trusted domain to local
administr
Date: Tue, 13 Jun 2006 06:01:02 -0700
Lines: 18
Message-ID: <7B5ADFF6-C03F-4AE3-ADA0-D3DE4306ED29@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.windows.server.migration
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.windows.server.migration:24045
NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.windows.server.migration

I want to test the domain migration. I have set up two domains - called A
and B.

I am stuck as the point where you have to add Domain Admins from the
trusted
domain into the local administrators group.

I can see the Domain Admins group from the trust domain but when I add
them
it tells me "the domain controllers required to find the selected objects
in
the following domains are not available ".

DNS looks to be fine - I have set up an AD integrated Primary for the main
domain and secondary for the trust domain. I can ping each of the domains
from the opposite servers.

Has anyone encountered this problem before and if so how did you get past
it?

Thanks for any help that you can offer.




.



Relevant Pages

  • Re: Trust Validation
    ... We are using DNS instead of WINS so the tool will show it not ... I actually am getting the trust to validate now. ... PortQry features, this is the backend tool for PortQryUI ...
    (microsoft.public.windows.server.active_directory)
  • Re: Not able to establish trust with another window 2003 domain
    ... Not the "Packet needs to be fragmented but DF set". ... I try to use my target domain to create a trust to one of my ... establish a trust to my source, its fail. ... i install a new server on each domain and try to create a DNS ...
    (microsoft.public.windows.server.active_directory)
  • RE: Trust between two Forests Fail
    ... WINS AND DNS are working. ... "THE trust has been validated. ... I can access their Active Directory from my side and can nodify users (using ... Niether side can see the other sides Donain in Windows Explorer " Network ...
    (microsoft.public.windows.server.active_directory)
  • Re: RPC server unavailable, unable to obtain RPC connection to domain controller
    ... Then try establishing the trust again using FQDN not Netbios. ... > I'm having a major problem with my domain controller. ... > 2 of them host Active Directory Integrated DNS zones. ... > that the name can be resolved and that the server is available. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forcfully (manually) removing a domain
    ... As Herb suggested, you ADSIEDIT and delete the object (of ... The trust is broken, ... I went in and changed the DNS settings to what you instructed. ... The reverse lookup zones ...
    (microsoft.public.win2000.active_directory)