Re: External Trust - unable to assign permissions



Hi,

Some of my comments are in-line...

"Wayne" <Wayne@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:26FB1715-08AE-4397-9298-3B4964C37EC6@xxxxxxxxxxxxxxxx
I have setup a 2 way external trust to a recently acquired domain(B) from
our
domain(A). Both domains are Windows 2003 Server and in mixed mode. Domain
Controllers are pointed to a common WINS database.
Issue- I am unable to assign permissions on a share to Global groups or
users between Domain(A) and Domain(B).

Proper and recommended way for doing this would be to create a Domain Local
Group in Domain B and assign this group permissions on resources. Then add
Global group from domain A to Domain Local Group in Domain B.

I have relied on Netbios to setup the share as the seperate DNS's are not
talking to each other yet.
I can \\Fileserver\sharename from a fileserver in Domain(A) from Domain(B)
but I am unable to assign NTFS permissions on the share on
Domain(A)\\Fileserver\sharename. I get there error (Name not found)
Question: Is Netbios sufficient to establish the share permissions for an
external domain?

It looks like you will have to fix some resolution problems. My advice is to
use DNS. Since you are running Windows Server 2003 you can use conditional
forwarding to configure DNS server in domains A and B to point to correct
servers for resolution. Personally I would fix name resolution (DNS) issue
first -- and then work on other issues that might remain.

Let me know if you need more help with this.

--
Mike
Microsoft MVP - Windows Security


.



Relevant Pages

  • Re: NT Domain to AD migration
    ... Windows 2000/XP always prefer Kerberos authentication, ... Server 2003 Active Directory service, ensure that you have designed a DNS ...
    (microsoft.public.windows.server.active_directory)
  • Re: Secondary DNS and PIX
    ... Of course I updated them with the DNS ... WINDOWS SERVER 2003 FOR SMALL BUSINESS SERVER, ... Windows SBS 2003 SP1 is available. ...
    (microsoft.public.windows.server.sbs)
  • Re: Find AD hostname from Linux command line
    ... The Windows XP workstation gets an IP ... "Register this connection's addresses in DNS" turned ON. ... If I am on a Linux server and do "ping lancelot.ad.mydomain.com", ...
    (microsoft.public.win2000.dns)
  • Re: Secondary DNS and PIX
    ... SBS SP1 was a very specific service pack comprising several ... Root hints for DNS means you leave the forwarders ... WINDOWS SERVER 2003 FOR SMALL BUSINESS SERVER, ...
    (microsoft.public.windows.server.sbs)
  • Re: Two Win2k3 questions ... Roaming Profiles & Access Privileges ...
    ... >DHCP, DNS, Print Server, and File Server responsibilities. ... lookup zone on Windows NT" ... http://support.microsoft.com?kbid=229873 "Delegate Control Wizard Cannot Be Used ...
    (microsoft.public.win2000.advanced_server)