1 Way Trust, Nested Groups & GPO's
i have 1 way external non transitive trust between 2 different forrests. domaina trusted domainb. servers windows 2003 , domain , forest functional level 2003
i can assign permissions folder in domainb giving ther pernmission domain local group (dl-group) in domainb. inside group have universal group domainma contains global group domaina contains users domaina want grant permissions to. works fine.
i have gpo in domainb adds dl-group above to local admin group on member servers when try log in servers using domaina account cannot. if add global group domaina in directly can access servers without issue.
can tell me if possible nest groups have done above or there step required on order nesting work regards local admin accounts.
thanks.
hi all,
fyi issue related firewall configuration.
the member servers in domainb need access on ports dc's on domaina in order group nesting work across different forests.
the ports are:
tcp
135
445
88
389
1025
udp
389
Windows Server > Directory Services
Comments
Post a Comment