security group checking within forest


hello

i have following domain controllers

forest.com

oak.forest.com

ash.forest.com

i have user testuser in domain users in ash subdomain.

domain users member of universal group testgroup in forest.com dc.

query against gc port on forest.com not able determine

that testuser member of testgroup

is memberof query limited in regard? i'm using nested group chain match also.

i thought gc aware of

nested group (domains users ash subdomain)

and determine user membership

should possible?

thank insight.

hi,

you might need global scope group, check link , detailed information in technet link useful understand , apply requirement.

https://technet.microsoft.com/en-us/library/cc755692(ws.10).aspx


regards, jim mscs - mcp disclaimer: posting provided no warranties or guarantees , , confers no rights. when see answers , helpful posts, please click vote helpful, propose answer, and/or mark answer



Windows Server  >  Directory Services



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file