I would start with 

nltest /sc_query:nt4domainname

Run on various 2k3 DCs.

 

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]
Sent: Wednesday, October 27, 2004 3:01 PM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Odd trust behavior

We've begun adding our first servers, all 2003, into our first AD domain
(running in 2003 mode).  This domain has a two-way trust with one of our
NT4.0 domains.  We need to add a global group from the NT4.0 domain into the
Administrators group on the server.  We're able to do this.  However, when
we go back into the Administrators group all we get is the SID and a
question mark.  This also results in the members of that group being unable
to access the server.  We can remove the group and readd the group but it
still converts to just the SID and the question mark.  We've also removed
one of the servers with this problem from the domain, readded, and readded
the group to Administrators, but no luck.

I believe that there's something simple and obvious that we're missing.
WINS checks out fine.  We're able to map drives manually to each other from
both the PDC of the trusted domain and from the server in question.

Any ideas?
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to