Click here to get back home

Adding a User from One Domain to a Group in Another Domain

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Adding a User from One Domain to a Group in Another Domain Andrew Hayes 08-18-2006
Posted by Andrew Hayes on August 18, 2006, 12:12 am
Please log in for more thread options
I have 2 W2K3 domains with a two-way trust relationship between them, and I
would like to add a user from Domain A to one of the groups in Domain B.
Unfortunately, all I can seem to do is only add users from Domain A to one
of the Built-in groups of Domain B, not to any of the groups in the Users
container.

Is this at all possible?



Posted by Roger Abell [MVP] on August 18, 2006, 3:30 am
Please log in for more thread options
Groups may be moved in or put of the Users container, so one cannot
guess (fully) what you are seeing there. However, it is a rule that you
may not add externals to domain globals. While natively there are some
domain locals in Users, Builtins holds domain locals, and Users does not
hold builtin groups.


>I have 2 W2K3 domains with a two-way trust relationship between them, and I
>would like to add a user from Domain A to one of the groups in Domain B.
>Unfortunately, all I can seem to do is only add users from Domain A to one
>of the Built-in groups of Domain B, not to any of the groups in the Users
>container.
>
> Is this at all possible?
>



Posted by Andrew Hayes on August 18, 2006, 6:26 am
Please log in for more thread options
Well, I had wanted an Enterprise Admin account on Domain A to also be
Enterprise Admin on Domain B, but I guess that's not normal. Probably I
should of added Domain B to the Domain A Forest, rather than making it it's
own Forest.

> Groups may be moved in or put of the Users container, so one cannot
> guess (fully) what you are seeing there. However, it is a rule that you
> may not add externals to domain globals. While natively there are some
> domain locals in Users, Builtins holds domain locals, and Users does not
> hold builtin groups.
>
>
>>I have 2 W2K3 domains with a two-way trust relationship between them, and
>>I would like to add a user from Domain A to one of the groups in Domain B.
>>Unfortunately, all I can seem to do is only add users from Domain A to one
>>of the Built-in groups of Domain B, not to any of the groups in the Users
>>container.
>>
>> Is this at all possible?
>>
>
>



Posted by Roger Abell [MVP] on August 18, 2006, 2:48 pm
Please log in for more thread options
One of the leading reasons for separate forests is to effect strong
administrative separation, the containment it CAN provide, etc..
It appears you do not actually want that. You probably should
examine your objectives for funtionalities, operational model,
risk containment, etc.

> Well, I had wanted an Enterprise Admin account on Domain A to also be
> Enterprise Admin on Domain B, but I guess that's not normal. Probably I
> should of added Domain B to the Domain A Forest, rather than making it
> it's own Forest.
>
>> Groups may be moved in or put of the Users container, so one cannot
>> guess (fully) what you are seeing there. However, it is a rule that you
>> may not add externals to domain globals. While natively there are some
>> domain locals in Users, Builtins holds domain locals, and Users does not
>> hold builtin groups.
>>
>>
>>>I have 2 W2K3 domains with a two-way trust relationship between them, and
>>>I would like to add a user from Domain A to one of the groups in Domain
>>>B. Unfortunately, all I can seem to do is only add users from Domain A to
>>>one of the Built-in groups of Domain B, not to any of the groups in the
>>>Users container.
>>>
>>> Is this at all possible?
>>>
>>
>>
>
>



Posted by Andrew Hayes on August 20, 2006, 8:46 pm
Please log in for more thread options
True. I would of prefered to not have seperate forests, but at the time my
knowledge was limited to NT4 and time was short, so rather than study up on
how to add a domain to an existing forest, I just created an entirely
seperate forest and domain and then used trust relationships to allow access
to the other domains resources.

My bad, I know, but now it would be very difficult to get these seperate
forests put into the one I already have.

> One of the leading reasons for separate forests is to effect strong
> administrative separation, the containment it CAN provide, etc..
> It appears you do not actually want that. You probably should
> examine your objectives for funtionalities, operational model,
> risk containment, etc.
>
>> Well, I had wanted an Enterprise Admin account on Domain A to also be
>> Enterprise Admin on Domain B, but I guess that's not normal. Probably I
>> should of added Domain B to the Domain A Forest, rather than making it
>> it's own Forest.
>>
>>> Groups may be moved in or put of the Users container, so one cannot
>>> guess (fully) what you are seeing there. However, it is a rule that you
>>> may not add externals to domain globals. While natively there are some
>>> domain locals in Users, Builtins holds domain locals, and Users does not
>>> hold builtin groups.
>>>
>>>
>>>>I have 2 W2K3 domains with a two-way trust relationship between them,
>>>>and I would like to add a user from Domain A to one of the groups in
>>>>Domain B. Unfortunately, all I can seem to do is only add users from
>>>>Domain A to one of the Built-in groups of Domain B, not to any of the
>>>>groups in the Users container.
>>>>
>>>> Is this at all possible?
>>>>
>>>
>>>
>>
>>
>
>



Similar ThreadsPosted
Adding another domain users to your local domain admin group December 28, 2005, 12:19 pm
removing user from domain users group doesn't help June 23, 2006, 4:15 pm
Create User and Auto Assign to Domain Security Group January 31, 2007, 12:27 pm
Allowing a Domain User Admin Rights to a Couple of Domain Servers June 29, 2005, 8:13 pm
domain access control for local user of domain computer? April 3, 2008, 5:14 pm
ENTERPRISE DOMAIN CONTROLLERS Vs Domain Group Domain Controllers December 30, 2005, 3:08 am
Default Domain Users group March 24, 2008, 1:59 pm
domain Backup Operators group question April 20, 2006, 8:53 am
Windows Vista Group Policies in a Server 2003 SP1 Domain environment May 11, 2007, 9:21 am
Adding multiple entries for the same user with xcacls... July 19, 2007, 2:21 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap