G
Guest
Hello
I have previously asked about Global Catalog and the attribute memberOf. I now have a follow-up question that better describes my problem
I have the following domain structure
company.co
se.company.co
dk.company.co
us.company.co
(a total of 30 subdomains
I have defined a total of 3 Universal Groups, containing members from more than one sub domain. Now I would like to query the Global Catalog across all domains for a specific user and get a list of these 3 groups (no other groups are of interest) in the attribute memberOf
I can only modify the connection string, not the application used. For testing, I use LDAP Browser from Softerra. I have chosen the main domain controller with a Global Catalog on it. The connection string is "dc01.company.com:3268"
And here is my question: Why is it, that I can see the group membership using memberOf for some users and not for others? It's less than 2% of the users that has the attribute memberOf (but when it's there, my 3 groups are there!). What about the other 98%? Why isn't memberOf visible for them
If I try a subdomain instead (and another Global Catalog), memberOf is correct, but I can only see users from that subdomain
Is it possible to configure Active Directory so that memberOf is visible for my 3 groups at the "company.com" level for ALL users
I am on Windows 2000 but will start a migration to Windows 2003 soon. Will 2003 solve this issue
Regards
Mikael
I have previously asked about Global Catalog and the attribute memberOf. I now have a follow-up question that better describes my problem
I have the following domain structure
company.co
se.company.co
dk.company.co
us.company.co
(a total of 30 subdomains
I have defined a total of 3 Universal Groups, containing members from more than one sub domain. Now I would like to query the Global Catalog across all domains for a specific user and get a list of these 3 groups (no other groups are of interest) in the attribute memberOf
I can only modify the connection string, not the application used. For testing, I use LDAP Browser from Softerra. I have chosen the main domain controller with a Global Catalog on it. The connection string is "dc01.company.com:3268"
And here is my question: Why is it, that I can see the group membership using memberOf for some users and not for others? It's less than 2% of the users that has the attribute memberOf (but when it's there, my 3 groups are there!). What about the other 98%? Why isn't memberOf visible for them
If I try a subdomain instead (and another Global Catalog), memberOf is correct, but I can only see users from that subdomain
Is it possible to configure Active Directory so that memberOf is visible for my 3 groups at the "company.com" level for ALL users
I am on Windows 2000 but will start a migration to Windows 2003 soon. Will 2003 solve this issue
Regards
Mikael