Domain Global (in trusted domain) to Domain Local in trusting domain
I know its possible as I can do it manually
But when I do it manually it
adds an entry (with a CN= type entry ) into ForeignSecurityPrincipals
adds the ForeignSecurityPrincipals object into the Domain Local Group
and I'm trying to work out how to do that in a script
"Al Dunbar [MS-MVP]" wrote in message
>
> "Ross" wrote in message
>
> > I am attempting to add groups from a trusted domain as members of groups
> on
> > my domain
> > I can do this for groups in the domain but not from another domain
>
> What types of groups, domain local, global, or universal? Only certain
> combinations are possible.
>
> /Al
>
> > I notice if I do it manually then list the members I get a result as
> >
>
CN=S-1-5-21-2055828564-438778298-1367285435-70415,CN=ForeignSecurityPrincipa
> > ls,D
> > C=NA,DC=SYM,DC=com
> >
> > I.e its a reference into the local domain
> >
> > Does anyone know how to set this up so I can add the Foreign name in to
my
> > domain and then add it in?
> >
> > TIA
> >
> >
> >
>
> >> Stay informed about: Script to add Group from a trusted domain