Administrative rights over NT4 - Win2K trust.

S

SteveK

I've got an nt4 domain and a win2k AD forest conected
over a 2way trust. The trust seems to work fine, from
each side of the trust you can add users to groups.
However the trust doesn't seem to function in that adding
the administrator on one side of the trust to the
administrators group on the other side doesn't give full
access.
As as example i've tried to run backup exec on the w2k to
back up servers on both domains. As I tried to push out
the remote client to a server on the nt4 domain i was
informed that the administrative account didn't have
permissions yet it is a members of administrators on both
sides. I could connect and push out the agent using the
nt4 administrators account.
Running Exchange administrator across the domain won't
work even though the w2k account has service account
admin permissions.
There are quite a few other similar issues that have
occoured.
Any ideas as to what the problem might be?
I've tried setting up the trust again.

Thanks in advance.
 
J

Joe Richards [MVP]

Adding a group from the W2K domain to the administrators group on the NT4 domain does not make the W2K Domain users in
that group NT4 Domain Admins and vice versa. You are only getting into the administrators group which gives you admin
rights over the domain controllers. You don't have anything over member servers and workstations of the domain. You
would have to add that group the administrators group of every domain (non-dc) machine separately.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top