Re: Accessing Resouces in another forest

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 03/19/05

  • Next message: Robert Moir: "Re: Adding Computers to the Domain (AD)"
    Date: Sat, 19 Mar 2005 16:06:05 -0600
    
    

    I thought that universal groups could only contain groups from within the
    forest. I have a two way forest trust set up between two Windows 2003
    forests in my test network, verified forest trusts, and verified proper dns
    name resolution. When I try to do as you want, I only find the domains in
    the same forest to choose from as possible places to add members groups
    from. I have tried this from each forest. However I have no problem adding a
    universal group from the trusted forest to a domain local group on the
    trusting forest. You might also want to post in an Active Directory
    newsgroup to see if anyone over there has actually been able to do such as
    described in the article you posted. --- Steve

    "jack tinker" <jt@tex.com> wrote in message
    news:423c7b91$0$75061$892e0abb@auth.newsreader.octanews.com...
    > Hi,
    >
    > According to Microsoft documentation,
    > http://www.microsoft.com/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/x_c_forestauthentication.asp
    >
    >
    > "Create a universal group in the resource forest, and then add all global
    > groups from the other forest (or forests) that need similar access as
    > members of the universal group.
    > For example, both the employees in the Sales Department and Accounting
    > Department global groups located in ForestA use similar print resources
    > located in ForestB. Create a universal group called Print Users in Other
    > Forests in ForestB, and add both the Sales Department and Accounting
    > Department global groups from ForestA as members.
    > Universal groups are used primarily to group together two or more global
    > groups (possibly from other forests) into one group for the resource
    > domain."
    >
    >
    > I just can't get this to work. Has anyone else added global groups from
    > other forests as members of a Universal group?
    >
    > btw. I have a transitive forest trust in place.
    >
    >
    > Thanks,
    > JT
    >


  • Next message: Robert Moir: "Re: Adding Computers to the Domain (AD)"

    Relevant Pages

    • Re: Cross Forest Administration
      ... Given that EA is a Universal Group it can ... contain objects from another forest is Domain Local. ... Enterprise Admins is a Universal group. ... users and trusts Forest C. Forest B holds resources used by internal ...
      (microsoft.public.windows.server.active_directory)
    • RE: restricted groups?
      ... transitive trust relationship between all domain in the forest, ... > impression that you create a Universal Group and add the Domain Admins from ... > A global group can contain other global groups and accounts from the same ... > other domain local groups from the same domain that the group belongs to. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Cross Domain privialges for Domain Admins
      ... Since the post you are replying to is an older post, and the person that originally posted possibly has a different setup than yours, it would probably be better that you started fresh and posted your own new thread and stated your current setup, what operating system version, what domain and forest functional levels are set to, as well as if domain1 and domain2 part of the same forest, different forest with a forest trust, two way NTLM trust, how is DNS setup between the domains or the forest trust, is there a DNS parent-child delegation in the forest, etc. ... and you created the Universal group in a child domain. ... Create a global group in domain 1 and place the user account(domain ...
      (microsoft.public.windows.server.active_directory)
    • RE: restricted groups?
      ... > transitive trust relationship between all domain in the forest, ... >> impression that you create a Universal Group and add the Domain Admins from ... >> A global group can contain other global groups and accounts from the same ...
      (microsoft.public.windows.server.active_directory)
    • Re: Can I permission a GPO to an univesal group ?
      ... same forest), you can add Users from different child domains to the Universal ... In the security filter of the GPO, check to make sure the READ and APPLY ... GROUP POLICY are set to 'Allow' for your Universal group, ... > an OU where I have a terminal server. ...
      (microsoft.public.windows.terminal_services)