Re: Domain Admin Access across Trusted domains

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 04/12/05

  • Next message: Viking 55: "User Profile blocks internet access"
    Date: Mon, 11 Apr 2005 16:04:25 -0700
    
    

    You may have a DNS issue.
    If both domains are using Windows DNS and are W2k3 then
    you could resolve this with conditional forwarding. Else,
    you would need to establish secondary zones each in the
    other domain so that both can resolved the AD supporting
    DNS records of the other.

    You should expect to not be able to add external groups into
    your domain global groups. You should be able to see the
    trusted domain in the list of locations in the user/group object
    picker, and to then add from the external as long as you are
    not attempting to next externals into your globals.

    -- 
    Roger Abell
    Microsoft MVP (Windows  Security)
    MCSE (W2k3,W2k,Nt4)  MCDBA
    "DevGD" <DevGD@discussions.microsoft.com> wrote in message
    news:AD20CA04-47BE-4EF3-BE8C-51063716CBA2@microsoft.com...
    > The trust is a two way external trust. I can not add members from the
    trusted
    > domain to groups on my domain. I can only add access on the folder/file
    > level. How can I add myself to the domain admins group or even the
    enterprise
    > admins group? When I open the group and select add on the members tab, I
    can
    > not see my domain to add my account.
    >
    > Any ideas?
    >
    > Thanks
    > Dev
    >
    > "Roger Abell" wrote:
    >
    > > If your machine is in domain that trust them, then you
    > > need an account in the trusted domain.  If theirs is trusting
    > > yours, then they could adjust membership of their Domain
    > > Admins group to add your account (they cannot add your
    > > Domain Admns group as it would be global in alien global)
    > >
    > > -- 
    > > Roger Abell
    > > Microsoft MVP (Windows  Security)
    > > MCSE (W2k3,W2k,Nt4)  MCDBA
    > > "DevGD" <DevGD@discussions.microsoft.com> wrote in message
    > > news:B7D22334-5383-4CA6-8B74-885D58221845@microsoft.com...
    > > > Is there a way for me to have administrator rights on a domain that I
    > > trust
    > > > with my domain? I just merged with a company and have established an
    > > external
    > > > trust with their network. I am now incharge of all active directory
    for
    > > the
    > > > whole company and would like to be able to access their AD from my pc
    > > > directly.
    > > >
    > > > Any help would be much appreciated.
    > > >
    > > > Thanks
    > > > Dev
    > >
    > >
    > >
    

  • Next message: Viking 55: "User Profile blocks internet access"

    Relevant Pages

    • RE: Trust between two Forests Fail
      ... WINS AND DNS are working. ... "THE trust has been validated. ... I can access their Active Directory from my side and can nodify users (using ... Niether side can see the other sides Donain in Windows Explorer " Network ...
      (microsoft.public.windows.server.active_directory)
    • RE: Guidence required in the low level workings of Domain Trusts
      ... Everything is working fine with the trust and DNS but that doesn't mean it ... How to optimize pass-through authentication of user accounts after you ... How Domain Controllers Are Located in Windows ...
      (microsoft.public.windows.server.active_directory)
    • Re: Trusts between 2 Windows 2000 servers
      ... It sounds like the name of PDC for the remote domain cannot be resolved. ... That's usually a DNS issue. ... 312003 - Unable to Establish an Explicit Trust Between Windows 2000-Based ... > If this domain is Windows domain, the trust cannot be setup until the ...
      (microsoft.public.win2000.advanced_server)
    • Re: Trusts already setup but cant browse user account except DC
      ... All the domain is using ADI dns, ... Actually would like to add that you can setup cross forests trust in Win2003 ... have you created the trust in both directions? ... Microsoft Windows MVP - Windows Server - Directory Services Security Is Like An Onion, ...
      (microsoft.public.win2000.networking)
    • RE: How to create trust relationship between Windows 2003 Server (domain controler) and Windows NT 4
      ... relationship between windows NT and Windows 2003 by following the ... Establish Trusts with a Windows NT-Based Domain in Windows Server ... How to Create a Trust Relationship ... Create a Two-Way Trust Relationship ...
      (microsoft.public.win2000.security)