Posts Tagged ‘Group Membership in Multi-Forest Scenarios’
2003 server - Sunday, March 2, 2008 1:50 - 0 Comments
Group Membership in Multi-Forest Scenarios
Clearing up uncertainty around some Microsoft documentation on how groups can be nested.
If your organization has deployed Active Directory in a multi-forest scenario (for example through a merger or acquisition with another company) and you need to add users or groups in one forest to a group in the other forest, the group in the other forest must be a domain local group. You might thing from reading the Microsoft documentation at http://msdn2.microsoft.com/en-us/library/ms677609.aspx that you could also use universal groups for this purpose since it says there that “A universal group can contain other universal groups, global groups and accounts from any domain in any forest”. However, this is incorrect—universal groups can only contain users or groups from the same forest, not from different forests.
Article written by MyComputerAid.com