Tech Support > Microsoft Windows > Windows Server > Can't add parent domain accounts to child domain groups
Can't add parent domain accounts to child domain groups
Posted by andy on April 9th, 2005


We have a single forest with 3 child domains running win2k3 Native, we added
a forth child domain, which everything went great, made it native too, we
cant access any accounts in the parent domain, to add them to groups in the
child domain. we checked all logs in the child domain and parent domain,
everything looks great, from all other child domains everything looks great.
But for some odd reason when ever we select the add members and select the
location, we can't see any objects from the Parent domain.
Does anybody have any clues?

DNS/Replication/Logs all say everything is operating OK.
I've built the 3 other child domains without this roadblock.
I want to add the Parent domain universal group to the


Posted by Todd J Heron on April 9th, 2005


Hi,

A global group can only contain users from its own domain.
Universal groups can only contain users within their own forest.
Domain Local groups can contain users from any trusted domain or forest.

--
Todd J Heron, MCSE
Windows Server 2003/2000/NT; CCA
----------------------------------------------------------------------------
This posting is provided "as is" with no warranties and confers no rights

Posted by nmayes on April 9th, 2005


I just want to clarify the issue and correct me if I'm reading this
wrong:

domain and verify it can resolve the parent domain, etc.


Posted by andy on April 11th, 2005


We are trying do add a the Domain Admins global group to the Administrators
DLG, the forest is configured as Windows 2003 Server mode. AD integrated DNS
for Child domain on both forward and reverse lookups.
"nmayes" <nwmayes@gmail.com> wrote in message
news:1113076076.841979.51860@o13g2000cwo.googlegro ups.com...


Posted by andy on April 11th, 2005


Well, it looks like everything is fine now. I guess it took more than 24
hours for AD to replicate objects and properties.

We didn't do anything, it just works. The mystery is time.

"andy" <avenson@anvencorp.com> wrote in message
news:%236Yrw1pPFHA.2132@TK2MSFTNGP14.phx.gbl...