Re: NT4 and 2000 Trust

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 04/29/05


Date: Fri, 29 Apr 2005 00:13:38 -0500

You should be able to. You should see a list of trusted domains to choose a
user/group from when you try such if the trust is correctly configured. I
don't understand why he won't even let you try. --- Steve

"Ken Loveless" <KenLoveless@discussions.microsoft.com> wrote in message
news:324B1B61-098F-43B3-9973-27CF6D3A1843@microsoft.com...
> NT4 domain trusts the 2000 domain, but not vice versa
> Can I add a user from the 2000 domain to a local domain group in the NT4
> domain?
>
> We are doing a migration and there is a subset of computers that have the
> NT4DOMAIN\APPSAdmins domain local group in the local administrator group.
> If
> I can add the 2000Domain\user account to the NT4DOMAIN\APPSAdmins group,
> it
> would save me a little bit of time because I could script a lot of the
> security changes that need to be made using the 2000Domain\user account
> that
> would have access to change security as well as be able to browse AD in
> the
> 2000 domain.
>
> The domain admin will not even let me try to do it. Says "It's NT, so it
> won't work." Seems to me is should, somehow.



Relevant Pages

  • Re: External trust & resources sharing
    ... It's not clear the direction of trust. ... > But if I am trying to search for this domain local group from SQL server ... I can not found it - only global groups are listed. ... this sounds like you're not in native mode. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Global Group or Universal Group???
    ... Create a trust, you could then have a domain local group and populate all ... users in the second domain to have access to a database in the first ...
    (microsoft.public.windows.server.active_directory)
  • Re: trusts, credentials, and authentication
    ... Without the trust, NETLOGON tries to ... the domain credentials are used as there's a secure channel between ... You need to set permissions in the trusting domain. ... assign the permissions to the domain local group. ...
    (microsoft.public.windows.server.active_directory)