PDA

View Full Version : 70-640 adding universal group as member of global group error


ice22
09-08-2009, 04:13 PM
Hi

I'm just watching through and trying the method of adding a universal group to a global group of another domain. But I'm getting error saying it cannot find or locate user, and please wait 15mins for replication to take place to the global catalog. I have follow the steps exactly, but are still getting the same error.

I have try using repadmin/ syncall, but still the same

Anyone know why this is happening,

Thanks

texasit
09-08-2009, 07:27 PM
My understanding is for a single domain forest you would nest a Global group in a Domain Local group and for a multi domain forest you would nest a Global group in a Universal group that is nested in a Domain Local group.

G -> DL

G -> U -> DL

Remember you create the NTFS permissions on the DL group.

ice22
09-08-2009, 11:07 PM
Hi

I'm sure its done correctly, but I'm unsure how to force replication between the two domain.

Domain local group in globomantics.com, universal in na.globomantics.com

But everytime I try add the universal into the domain local, it brings the same error saying the user may not exist, and that replication to global catalog could take upto 15mins

flipper
09-09-2009, 01:28 PM
Don't forget you need to setup a trust. As for adding the group. The group that you want to add the Global Group to needs to be a domain local group first not a universial.

You'll need to change the group to universial first then change it to domain Local.