Group Scope issue


team,

merry chrismas & advanced happy new year. support.

i have 1 query regarding group scope - below scenario.

we have 1 empty root forest 5 child domains. granted dns readonly console different admins diffrent domains.

permission granted "domain local" group & added global groups diffrent domains. working fine.

if granted permission via universal group & added global groups universal groups. getting access denied dns console.

my case single forest. believe universal group can work within same forest. worng in situation?


aliahmurfy

it might problem in reading universal group members.

could please check compliant best practices assigning fsmo roles? can see that: http://www.windowsdevcenter.com/pub/a/windows/2004/06/15/fsmo.html

rule 2: infrastructure master should not placed on gc.

  • tip: make sure infrastructure master has gc in same site direct replication partner.
  • exception 1: it's ok put infrastructure master on gc if forest has 1 domain.
  • exception 2: it's ok put infrastructure master on gc if every dc in forest has gc.


this posting provided "as is" no warranties or guarantees , , confers no rights.

get active directory user last logon

create active directory test domain similar production one

management of test accounts in active directory production domain - part i

management of test accounts in active directory production domain - part ii

management of test accounts in active directory production domain - part iii

reset active directory user password



Windows Server  >  Directory Services



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file