Jump to content

Recommended Posts

Posted

Morning all,

 

We're in the process of migrating between a 2012 domain and a 2016 one, we've got a trust set up between them and I want to enable users on the new domain to access files on the old one. It's a long, long while since I last used a domain trust (server 2000 was involved I think) so I'm hazy about how to use it, if my memories of that time are even relevant any more.

 

I thought I could simply add groups from the new domain into groups on the existing domain and thus automatically delegate them the same rights, but when I try to do this in ADUC the new domain doesn't appear in the locations list when I click on 'add'.

 

The only route I can seem to find is to go to the existing directories and shares and add the new groups with the same rights as the old ones, which seems like a hugely laborious and error-prone process, I'm left thinking there must be a better way and that I must have missed something.

 

Can anyone enlighten me, or alternatively crush my hopes ? :)

Posted (edited)

Can't really remember as it's been so long, all I can remember is that you can only see global and universal groups from the "other" domain. Although now I've written this I've realised how obvious that is (as domain local groups are called...domain local).

 

I seem to remember there being a few different types of trust between domains, again not much help as it's been a long time since I did trusts which weren't just parent-child.

 

 

Edit: Oh wait, just looked on here (where we have forest trusts, but they're done by the trust IT guys not me), you need to add them the other way round:

 

Edit a group, on the Members tab you can only add things from your current domain, on the Member Of tab you can select another location.

Edited by Katy
  • Thanks 1
Posted (edited)
Can't really remember as it's been so long, all I can remember is that you can only see global and universal groups from the "other" domain. Although now I've written this I've realised how obvious that is (as domain local groups are called...domain local).

 

I seem to remember there being a few different types of trust between domains, again not much help as it's been a long time since I did trusts which weren't just parent-child.

 

 

Edit: Oh wait, just looked on here (where we have forest trusts, but they're done by the trust IT guys not me), you need to add them the other way round:

 

Edit a group, on the Members tab you can only add things from your current domain, on the Member Of tab you can select another location.

 

Hmmm, that seems to work but it only shows me domain local groups on the other domain.

 

Edit - which are the only groups that groups from a trusted domain can be added to. Ho hum, seems my old domain is not well set up for this.

Edited by dcwhitworth

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...