depends on which group-type you're using - and which OS...
 
if you're connected to a GC, the Universal Group (UG) memberships should be visible on the User - however, you'll never see the Domain Local Group membership of a user if the group is in a different domain.
 
rgd. UGs - although the user's membership to these in any domain of the forest are available on the GCs (not on DCs), and although they're displayed in ADUC of Win2000, you'll no longer see them by default in Win2003/XP ADUC (a new filter was added so that GCs only show what DCs of the same domain know of...).
 
With Win2003 SP1 and/or hotfix for XP you can change that behaviour - check out 

http://support.microsoft.com/default.aspx?scid=kb;en-us;833883



From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dean Wells
Sent: Donnerstag, 30. Juni 2005 18:51
To: Send - AD mailing list
Subject: RE: [ActiveDir] ADUC Group Viewing

This is expected since only the group truly knows its entire membership (with the exception of the primary group whose relationship is expressed only by the user object).

--
Dean Wells
MSEtechnology
* Email: dwells@msetechnology.com

http://msetechnology.com

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond
Sent: Thursday, June 30, 2005 12:38 PM
To: [email protected]
Subject: [ActiveDir] ADUC Group Viewing

One of the app groups here told me he needed rights to see users’ membership in groups throughout the forest. Ok, fine. So I go in ADUC and look at a user which meets this criteria, and I as an ent admin only see the users groups in the local domain. If I go look at the group in the other domain, it shows the whole membership from the forest. Is this expected behavior or is something wrong here? I have no idea, having never tried to do what the guy wants to do.

 

Thanks,

brian

 

Reply via email to