Tech Support > Microsoft Windows > Windows CRM > NT4 Trust 2003 AD Full - CRM Deployment sees no users.
NT4 Trust 2003 AD Full - CRM Deployment sees no users.
Posted by TheKlemer on July 14th, 2006


Hello Again all,

Ok, again, documentation says it's doable so here goes:

I have a domain that is in it's own little world (lets just say it's called
MSCRM).
It has 3 Servers:
1. Active Directory Server - Running 2003 AD Level on Windows 2003 Standard
2 GB ram. Also setup DNS on this box for the other 2, reverse and forward,
etc,..all working fine.

2. MSCRM Server - Running Microsoft CRM 3.0 Professional on Dual 3 GHz P4
Procs

3. MSSQL Server and reporting services - Running SQL 2005 Standard SP1 on
Dual 3 GHz P4 Procs

Ok, so we installed everything and it's all in it's own little world, and
what do you know, everything works perfectly. All boxes can authenticate to
eachother in any way shape or form through CRM or locally. Reports as well,
which was a previous issue we've resolved.

We then setup in DNS on a box outside both domains all 3 boxes with A and
reverse so that computers outside our "CRM" domain but still within our
network could nslookup both ways, and that's all workin fine too.

Here comes the fun:
Now, we go to setup a trust between AD 2003 and NT4 Service pack4 domain
controller.

Read everything there is to read about it, and got the trust setup just
fine. Heck I even added the admistrator of the NT4 domain to the
Administrators group on AD and vice versa on NT's global admin group. I left
SID Filter on (not sure if this has any effect).

We can see eachother, share resources, browse PC's, the whole bit.

Now, I create a new local domain group. I add a user from the NT Domain to
it, all is well

I go into Microsoft CRM or Deployment Manager and the only users they are
capable of even seeing are the ones created in active directory. Even though
i've clearly added NT 4 users over.

Any ideas?? Diable SID Filtering?? maybe some setting that will allow it all
to function...

I'm not horribley concerned about security between domians as the
controllers and users are all in the same building.

I just want to open the world up to both DC's and get MSCRM to see the NT4
users.

Thanks again,

--
JK

Posted by Peter Lynch on July 15th, 2006


Well, I would start by service packing your the NT domain controllers to
SP6a.

(NT SP4 is donkeys years old!)

Peter Lynch


"TheKlemer" <TheKlemer@discussions.microsoft.com> wrote in message
news:350E51D6-FE34-46AD-8E93-5E83D3EC60BC@microsoft.com...



Similar Posts