Problem with WindowsPrincipal IsInRole

From: Roy Chastain (NOSPAMroy_at_kmsys.com.NOSpam)
Date: 02/26/04


Date: Thu, 26 Feb 2004 12:46:44 -0500

I think that I have determined the following behavior. Any comments
would be appreciated.

I have a 2k domain in mixed mode (lets call it D2K). I have an NT 4
domain with 2 way trust to the D2K domain (lets call it DNT4).

If I create a GLOBAL group in D2K then WindowsPrincipal IsInRole
appears to work correctly. The only problem is that I can not put
members of the DNT4 domain into the GLOBAL group.

If I create a Domain-Local group in the D2K domain (so I can add DNT4
members to it), then WindowsPrincipal IsInRole fails for all users in
the group. Members of D2K and DNT4 alike.

I don't really know if this is a DOTNET issue or an underlying issue
or something that I have done extremely wrong. Any ideas?

Thanks
-------------------------------------------
Roy Chastain
KMSystems, Inc.



Relevant Pages

  • Re: Nesting groups?
    ... How dose it not accept the members of the global group? ... "Anders" skrev i meddelandet ...
    (microsoft.public.win2000.active_directory)
  • Re: Problem with WindowsPrincipal IsInRole
    ... Good think DOTNET ... extra code. ... >> If I create a GLOBAL group in D2K then WindowsPrincipal IsInRole ... >> members of the DNT4 domain into the GLOBAL group. ...
    (microsoft.public.dotnet.security)
  • Re: User access between different forests.
    ... universal groups can only contain objects from the same forest, ... It's just a global group that is ... added to the administrators group on all domain members. ... Microsoft MVP - Windows Server - Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: User access between different forests.
    ... Yeah, this isn't as easy as you'd hope. ... admins as its a global group. ... It's just a global group that is automatically ... added to the administrators group on all domain members. ...
    (microsoft.public.windows.server.active_directory)
  • Debug and two versions of VS
    ... Computers are members of Active Directory (Windows ... Users are inserted in the global group ... Unfortunately the Debug Group membership does apply to ... How can I achieve the configuration in which domain user ...
    (microsoft.public.dotnet.general)