Forest to Forest problem
From: Don Woeltje (dwoeltje_at_sebh.org)
Date: 05/13/03
- Next message: venkat: "making file security in windows xp"
- Previous message: Debbie: "Want to bypass the logon feature?"
- Next in thread: Roger Abell [MVP]: "Re: Forest to Forest problem"
- Reply: Roger Abell [MVP]: "Re: Forest to Forest problem"
- Reply: Xiang Tu [MS]: "Re: Forest to Forest problem"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 13 May 2003 07:40:06 -0700
I know that this isn't a Windows XP Security problem (it's
a Windows 2000 Security issue), but I couldn't post to the
Windows 2000 Security Newsgroup. I keep getting an error
back saying No such groups. So I'll have to post it here.
Hypothetical:
You have Forest A and Forest B. Both Forests are running
Mixed Mode because both have NT domain controllers. Then,
Forest B finally finishes upgrading all of its servers
(obviously, this includes the DC's) to Win2K. Forest B has
two domains; an "empty root" domain and a child domain
beneath the empty root (the child domain being the
equivelant of what used to be the old NT 4 domain). Forest
B switches it's child domain from mixed mode to native
mode....but doesn't (for some inexplicable and unknown
reason) doesn't change it's empty root domain from mixed
mode to native mode; maybe the consultants just forgot to
do it. Now, after this takes place Forest B gets a request
from a user to be able to access resources in Forest A,
which is still in Mixed Mode. There are one-way trusts in
both directions between the two forests, each trusting and
trusted by the other. But the Admins in Forest A cannot
access any of the users or groups in Forest B (not even a
listing of those users and groups), so that they can find
that person and add that person, from Forest B, into a
group in Forest A (so that this person in Forest B can
access resources in Forest A).
Forest B has the same problem; the Admins in Forest B
cannot browse any of the user or group resources in Forest
A in order to add those users or groups into groups in
Forest B.
My question is:
Would this be caused by the fact that the child domain for
Forest B was switched into Native Mode but Forest A is
still running in Mixed Mode? If not, what things could
likely be causing this problem?
- Next message: venkat: "making file security in windows xp"
- Previous message: Debbie: "Want to bypass the logon feature?"
- Next in thread: Roger Abell [MVP]: "Re: Forest to Forest problem"
- Reply: Roger Abell [MVP]: "Re: Forest to Forest problem"
- Reply: Xiang Tu [MS]: "Re: Forest to Forest problem"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|