Networking Forums

Networking Forums > Computer Networking > Windows Networking > Allow administrator from external domain read access to my domain

Reply
Thread Tools Display Modes

Allow administrator from external domain read access to my domain

 
 
PMC1
Guest
Posts: n/a

 
      04-29-2009, 11:08 AM
Hi,

I'm want to allow an admin from an external domain access my active
directory so they can add a Global Security group from this domain
(DomainA) to the access control list of a share on the external domain
(DomainB). I want the admin in the external domain to only have Read
Access to this domain so giving the external Admin the password to an
administrator account on this domain is not going to work. So my
question is, when creating a user ID for the external admin to use,
what rights should I grant him to allow him read access to this domain
such that he can pull down groups from DomainA to be added to ACL's on
DomainB

Configuration:
Both domains are in completely seperate Windows 2003 Forests
There is a 1 way non transitive external trust from DomainA to DomainB
(i.e. the external domain trusts this domain but not the other way
round)

Thanks in advance for any advise

Paul
 
Reply With Quote
 
 
 
 
Ace Fekay [Microsoft Certified Trainer]
Guest
Posts: n/a

 
      04-29-2009, 10:49 PM
"PMC1" <(E-Mail Removed)> wrote in message
news:e7a94128-3b30-42a7-946d-(E-Mail Removed)...
> Hi,
>
> I'm want to allow an admin from an external domain access my active
> directory so they can add a Global Security group from this domain
> (DomainA) to the access control list of a share on the external domain
> (DomainB). I want the admin in the external domain to only have Read
> Access to this domain so giving the external Admin the password to an
> administrator account on this domain is not going to work. So my
> question is, when creating a user ID for the external admin to use,
> what rights should I grant him to allow him read access to this domain
> such that he can pull down groups from DomainA to be added to ACL's on
> DomainB
>
> Configuration:
> Both domains are in completely seperate Windows 2003 Forests
> There is a 1 way non transitive external trust from DomainA to DomainB
> (i.e. the external domain trusts this domain but not the other way
> round)
>
> Thanks in advance for any advise
>
> Paul


Since the trust is already in place, has B's admin simply tried to add a
user or group from A's domain to the resource?

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
Microsoft Certified Trainer
(E-Mail Removed)

For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

"Efficiency is doing things right; effectiveness is doing the right
things." - Peter F. Drucker
http://twitter.com/acefekay


 
Reply With Quote
 
Mathieu CHATEAU
Guest
Posts: n/a

 
      04-30-2009, 07:33 AM
Hello,

put the groups you want to delegate in an OU, and give him the rights to
manage these groups through dsa.msc.

Of course, domain admins group & others mustn't be in this OU (they are
in OU Users by default)

PLEASE DO NOT MULTIPOST IN NEWSGROUPS. THANKS

Cordialement,
Mathieu CHATEAU
french blog: http://www.lotp.fr
english blog: http://lordoftheping.blogspot.com


PMC1 a écrit :
> Hi,
>
> I'm want to allow an admin from an external domain access my active
> directory so they can add a Global Security group from this domain
> (DomainA) to the access control list of a share on the external domain
> (DomainB). I want the admin in the external domain to only have Read
> Access to this domain so giving the external Admin the password to an
> administrator account on this domain is not going to work. So my
> question is, when creating a user ID for the external admin to use,
> what rights should I grant him to allow him read access to this domain
> such that he can pull down groups from DomainA to be added to ACL's on
> DomainB
>
> Configuration:
> Both domains are in completely seperate Windows 2003 Forests
> There is a 1 way non transitive external trust from DomainA to DomainB
> (i.e. the external domain trusts this domain but not the other way
> round)
>
> Thanks in advance for any advise
>
> Paul

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Non-domain computers can't access domain file shares properly modem Windows Networking 6 04-20-2009 03:53 AM
Req: Windows System Administrator / Domain Migration Specialist Mike Linux Networking 0 01-04-2008 02:47 PM
Unable to access domain shares from a non domain computer Joe Thomas Windows Networking 7 06-26-2006 05:49 AM
Inconsistent Access to an external domain connected to my domain w J Windows Networking 4 05-02-2006 10:44 PM
Administrator on a Domain Controller in AD problem !!! maart206@hotmail.com Windows Networking 0 05-05-2005 10:34 AM



1 2 3 4 5 6 7 8 9 10 11