Jump to content

Recommended Posts

Posted

I have 3 domains - students, employees, and a resource domain with services that both domains use. They are running on Server 2008 at 2008 functional level. I'd like for IT users in the employee domain to be able to use Active Directory Users & Computers (ADUC) locally on their computers for all 3 domains rather than having to RDP into the other two domains.

 

Employee domain administrators can't administer the resource domain, and I assume that the lack of explicitly granted permission is why. Once I get that working I will do the same for the student domain.

 

There exists a one-way trust such that users on the employee domain can be granted access to stuff on the resource domain. For example, I can easily add any user from the student or employee domain to file permissions on a resource domain computer.

 

However, if in ADUC on the resource domain I try to add another domain's user to a Universal security group, which should work, I cannot even choose the domain. It doesn't show up when I click "Locations", and if I instead type the username preceded by the domain (or follow it with @domain), it fails.

 

Am I trying to do the right thing but failing, or am I going in a totally wrong direction?

Posted
Bump. Does anyone have separate Active Directory domains for employees and students, and administer both from a computer on one domain?
Posted

18 hours does not qualify you for a bump. How rude.

 

In answer: yes, I used to run a forest of four domains from one console, quite happily with a two-way trust. I'm not an expert though, I never dared play once I'd set it up.

Posted

Sorry, on other forums where I'm a member that's acceptable. I won't do that again here.

 

I have made a small bit of progress. I was able to add users from another domain to a local security group, but I can't add that group to the Domain Admins group. Is there a way to grant administration priveleges directly to the group?

Posted
Sorry, on other forums where I'm a member that's acceptable. I won't do that again here.

 

I have made a small bit of progress. I was able to add users from another domain to a local security group, but I can't add that group to the Domain Admins group. Is there a way to grant administration priveleges directly to the group?

 

Grant the group Full Control over the domain, or the branch of it you want them to manage?

 

Better for your purposes though might be to just choose to delegate control to those groups.

  • Thanks 1
Posted

Ah! I have never done that before. I've never worked on a large or complex enough AD to need to delegate that way; I've always just added users to the Domain Admins group.

 

I think I've got a few small bugs to work out but my problem is substantially solved now.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...