ronanian Posted April 12, 2010 Posted April 12, 2010 I have 3 domains - students, employees, and a resource domain with services that both domains use. They are running on Server 2008 at 2008 functional level. I'd like for IT users in the employee domain to be able to use Active Directory Users & Computers (ADUC) locally on their computers for all 3 domains rather than having to RDP into the other two domains. Employee domain administrators can't administer the resource domain, and I assume that the lack of explicitly granted permission is why. Once I get that working I will do the same for the student domain. There exists a one-way trust such that users on the employee domain can be granted access to stuff on the resource domain. For example, I can easily add any user from the student or employee domain to file permissions on a resource domain computer. However, if in ADUC on the resource domain I try to add another domain's user to a Universal security group, which should work, I cannot even choose the domain. It doesn't show up when I click "Locations", and if I instead type the username preceded by the domain (or follow it with @domain), it fails. Am I trying to do the right thing but failing, or am I going in a totally wrong direction?
ronanian Posted April 13, 2010 Author Posted April 13, 2010 Bump. Does anyone have separate Active Directory domains for employees and students, and administer both from a computer on one domain?
powdarrmonkey Posted April 13, 2010 Posted April 13, 2010 18 hours does not qualify you for a bump. How rude. In answer: yes, I used to run a forest of four domains from one console, quite happily with a two-way trust. I'm not an expert though, I never dared play once I'd set it up.
ronanian Posted April 13, 2010 Author Posted April 13, 2010 Sorry, on other forums where I'm a member that's acceptable. I won't do that again here. I have made a small bit of progress. I was able to add users from another domain to a local security group, but I can't add that group to the Domain Admins group. Is there a way to grant administration priveleges directly to the group?
powdarrmonkey Posted April 13, 2010 Posted April 13, 2010 Isn't the domain admins group domain-local?
jamesb Posted April 13, 2010 Posted April 13, 2010 Sorry, on other forums where I'm a member that's acceptable. I won't do that again here. I have made a small bit of progress. I was able to add users from another domain to a local security group, but I can't add that group to the Domain Admins group. Is there a way to grant administration priveleges directly to the group? Grant the group Full Control over the domain, or the branch of it you want them to manage? Better for your purposes though might be to just choose to delegate control to those groups. 1
ronanian Posted April 13, 2010 Author Posted April 13, 2010 Ah! I have never done that before. I've never worked on a large or complex enough AD to need to delegate that way; I've always just added users to the Domain Admins group. I think I've got a few small bugs to work out but my problem is substantially solved now.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now