Child/Parent Domain sanity Check

From: James Fabulous (James.Fabulous_at_hotmail.com)
Date: 09/28/05


Date: Wed, 28 Sep 2005 13:59:35 -0600

Having some issues that I'm trying to work through:
    A user from parent domain A wants to RDP to server in Child domain B
The user from A doesn't have a user account in B - but his account is a
member of a universal group in A which is a member of a universal group by
the same name in B that is a member of the administrators group of the
target machine.

Error is: "the specified domain does not exist or could not be contacted" ot
"The system cannot log you on because the domain is not available"
tried: user, password, A
        user@a.com, password
        A\user, password
        A.com\user, password
all fail. Even when we test with a domain admin from A we get the same
error.

This has previously worked, and from what I can tell via NLtests netlogon is
working properly and the domains are replicating normally. The DC for B can
see the member group from A and enumerate it's users on the members tab.
Target machine is 2000 running terminal services in administration mode.



Relevant Pages

  • Re: Message bouncing between two servers
    ... Basically she is a member of a group that is nested in one that sends to the ... (ie. departmental universal group, nested within company ... send to the company universal group. ... all refer to the SMTP connector/smart host problems, ...
    (microsoft.public.exchange.admin)
  • Re: Identify which users are missing from a group
    ... account objects a direct member of the Universal Group. ... user account objects you do not want to have 300 individual user account ... Group called 'Managers' and say that you have a Distribution Group called ...
    (microsoft.public.win2000.active_directory)
  • Re: AD - users and computers in child domain
    ... > DC1 GC IM ... Neighter user was shown as member of universal group from ... If you are looking at a Universal Group ... What the IM does is pull references for objects in other domains, ...
    (microsoft.public.windows.server.active_directory)
  • Re: changing group scope
    ... Changing group scope ... · Domain local to universal. ... want to change does not have another domain local group as a member. ... change does not have another universal group as a member. ...
    (microsoft.public.cert.exam.mcse)
  • Re: How to make a AD group member of the local administrators grou
    ... Can I use your script and replace the user ingo with the group info or do I ... Clemens de Brouwer ... that group to the local Administrators group. ... ' Check if user already a member. ...
    (microsoft.public.windows.server.scripting)