I have a two-way transitional forest trust between two windows 2003 domains,
domainA and domainB. The domain and forest functional levels on both domains
are "Windows Server 2003". The trust is working partially in that users
from domainB are able to logon to computers from domainA and visa-versa. In
addition, I am able to do things like add a user from domainB to a security
group of a pc in domainA. For instance, I am able to add user1@domainB to a
computer in domainA. However, what I am not able to do is add users from
domainB to security/universal groups on domainA. In fact, in ADUC on domainA
I am not able to select or view domainB, which I should be able to do. I have
a secondary DNS zone setup to domainB with zone transfers and that seems
to be working as I am able to ping a computer in domainB from domainA by
name. Can someone tell me why I am not able to add users from domainB to a
security group in domainA?
I previously had this request in the Active Directory newsgroup and could
not resolve the issue their so I thought I would try here.
Thanks in advance,
Bob
|