WS2012r2 - Cross-forest trust - Can add groups to user but when I open it again, groups are not listed

Hello Everyone,
I hope you can help me resolve this issue, I'm missing something but I don't know what.
I have 2 ws2012r2 domain controllers, each one with it's own forest (Lets call them A.com and B.com).
I have a validated 2 way external trust relationship between those domains.
I've added the domain admin "B\Administrator" to the DL group "A\Administrators", so I have permissions to modify everything on A.com
From "Active Directory Users and Computers" on B.com, I can see all users and "Domain Local" groups of A.com
From "Active Directory Users and Computers" on A.com, I can see all users and "Domain Local" groups of B.com
What I need: Add users from B.com to DL groups in A.com using the "B\Administrator" account
The problem: I'm able to open a user from B.com, add a DL group from A.com, click Apply, then OK.
But if I open the user again and go to the "Member of" tab, the group is no longer listed there.
If I go to the A.com domain and open the DL group membership tab, I can see the user from B.com listed there.
So there's something wrong, cause even If the user is listed in the group in A.com, It's not assigning the right permissions when trying to access the resources that group grants access to.
Any ideas what did I do wrong ot forget to do?
Thanks!

Hi,
Have you tried to take a force replication or refresh and then check the membership? Please verify DNS is well configured and we got a GC in both sides of the two forests.
In addition, please take a look at the below link:
Understanding the Global Catalog
Hope that may help
Best regards
Michael
If you have any feedback on our support, please click
here.
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

Similar Messages

  • I have a spinning wheel in Mail - stuck on trying to load a new message. I've force quit both Mail and my whole computer, but when I open mail again, it brings up the same new message - and the side bar curser is stuck in Drafts. What can I try to cancel

    I have a spinning wheel in Mail - stuck on trying to load a new message. I've force quit both Mail and my whole computer, but when I open mail again, it brings up the same new message - and the side bar curser is stuck in Drafts. What else can I try to cancel

    Can you log on to the email account via webmail in a web browser, view the email and delete it from there if necessary.

  • Hello apple, i bought a ear pod but when i open have 1 way are no sound can i change 1?

    i bought a ear pod but when i open have 1 way are no sound can i change?
    I buy from apple from February but when now i use its have a big problem, left hand side dint have sound? how can i do @@

    Bring it back to Apple Store.

  • I have added my hotmail email account to my ipod but when I open/delete emails it is not syncing with my computer. What can I do so that when I delete emails from my ipod, they show up as deleted when I access hotmail from my computer.

    I have added my hotmail email account to my ipod but when I open/delete emails it is not syncing with my computer. What can I do so that when I delete emails from my ipod, they show up as deleted when I access hotmail from my computer?

    If you like to set up the Hotmail account as an Exchange account, see this Apple support document.
    iOS: Hotmail, Live, or MSN email accounts
    B-rock

  • Question: When I want to send SMS and click on the contact, the contact came out with names and numbers, as if the whole contacts are there in the phone. When I open the contact, I can only see 3 contact names and the rest of 4000  contacts are not listed

    Question: When I want to send SMS and click on the contact, the contact came out with names and numbers, as if the whole contacts are there in the phone. However, when I open the contact, I can only see 3 contact names and the rest of 4000 plus contacts are not listed, and it makes you difficult to call through contact

    The iPhone remembers information about previous contacts.
    Complelely independently, you have a Contacts app with a contacts list.  It sounds like your contacts list has 3 names on it.  You need to add a few names.

  • I Can Add a new user, But the new user cannot logg in how can I solve this?

    Hi there. When I add a new user every thing works great except when I try to logg this new user. The computer freezers at the logging window with the processing bar working indefinetly. To fix it I have to AppleCtrlpower swich to get out and restrat the computer. I can only logg in as the administrator... Can any one help me and point me to a right solution. Thank you!

    Javivi:
    Welcome to Apple Discussions.
    It is difficult to tell why your new user account is not working, but one has to start some place.
    First try Starting up in Safe Mode. Log in with the original user account, the restart the computer normally and log into the original user account. Go to Applications > Utilities > Disk Utility. Launch Disk Utility. Select your HDD (manufacturer ID) in the left panel and First Aid in the main panel. Click Repair Disk Permissions. Quit DU.
    Go to System Prefs > Accounts and recheck the new account, especially the login options. If everything seems OK quit System Preferences and restart. Try logging into the new accounts. If you have problems force shut down and Start up in Safe Mode again.
    It may be easiest to just delete the new account and start over, as you do not yet have any data in it. However, if you want to continue to trouble shoot we can try it for a while.
    Please post back with a report of your experience and any questions or comments you may have.
    Good luck.
    cornelius

  • I can access the "Firefox Prefereences", but when the "about:preferences" starts, it will not let you access anything except the "General" tab.

    All of the other "tabs" show up on the tab menu, but when you click on them, only the "General" tab will be there. You can make changes to the items in the "General" tab, but nothing else. I am using a HP Pavillion dv7 laptop, running Ubuntu 13.10, and Firefox 29. This only started with version 29. Before everything worked.

    Works for me on Linux.
    Start Firefox in <u>[[Safe Mode|Safe Mode]]</u> to check if one of the extensions (Firefox/Tools > Add-ons > Extensions) or if hardware acceleration is causing the problem (switch to the DEFAULT theme: Firefox/Tools > Add-ons > Appearance).
    *Do NOT click the Reset button on the Safe Mode start window.
    *https://support.mozilla.org/kb/Safe+Mode
    *https://support.mozilla.org/kb/Troubleshooting+extensions+and+themes
    Create a new profile as a test to check if your current profile is causing the problem.
    See "Creating a profile":
    *https://support.mozilla.org/kb/profile-manager-create-and-remove-firefox-profiles
    *http://kb.mozillazine.org/Standard_diagnostic_-_Firefox#Profile_issues
    If the new profile works then you can transfer files from a previously used profile to the new profile, but be cautious not to copy corrupted files to avoid carrying over the problem
    *http://kb.mozillazine.org/Transferring_data_to_a_new_profile_-_Firefox

  • Can't add mailboxes to gmail but when I try the same procedure with Bell mail I don't get an edit button so can't add any mailboxes.

    I have 2 email accounts Gmail and Bell mail. I can add mailboxes to gmail but when I try the same procedure with Bell mail I don't get an edit button so can't add any mailboxes.

    Mailboxes can be added only to IMAP accounts. Is Bell setup as IMPAP or POP?

  • I want to ask why my invoice lost header title..in my mac i can see my invoice title..but when i open file lost my office name and address on number

    my invoice got my company name and address..when i see in my macbook can see the title..but when i open file to edit lost my title.many customer ask me why..
    i just know lost title.i did't change other setting in my number..hope can gv me answer..last week i use still ok..now lost it.

    Possible problem: You designed the invoice using Numbers '09 but you are now editing it in Numbers 3.  The company name and address are in a page header or footer, something Numbers 3 does not have so it deletes it from the document.
    Possible solution: Return to using Numbers '09.  It should still be in the Applications forlder on your computer.
    Another Possible Solution: Use a text box for your company name and address.
    If you are trying to use Numbers 3, you might want to see if your invoice will print correctly (with or without the company name and address)

  • Active Directory cross forest trust which are deployed in separate subscription

    Hi All,
    I know that this is not Azure forum, but I have a question related to Active Directory, Appreciate your understanding and letting me know your concerns about AD cross forest between two subscriptions of Azure.
    We have two separate subscriptions of Windows Azure under one Global Account, previously these two subscriptions are treated as a separate company and they are having separate forest and separate domain, these two companies does not have any site to
    site VPN with each other over the wan, but these two companies are having site to site connection with Azure for their own subscription respectively.
    Additional domain controller for both subscriptions are deployed in Azure in order to authenticate those servers which are already deployed in Azure
    Due to some reasons these companies are merging together and due to some reasons they want to have cross forest trusts between these two companies. As we do not have any WAN connection between these two companies the questions has been raised that can we
    do a cross forest trust between two Active Directories because these two are deployed in Azure and both companies active directories are deployed in Azure.
    Can we achieve this and how we can achieve this, I know that we can expose servers in Azure over the internet by creating endpoints and allow ACL in order to get connection from specific public IPs.
    My question is can we achieve this, does it supported from Microsoft. if yes then is there any thing we have to consider before deploying it.
    Thanks
    If answer is helpful, please hit the green arrow on the left, or mark as answer. Salahuddin | Blogs:http://salahuddinkhatri.wordpress.com | MCITP Microsoft Lync

    No, i am not using Windows Azure Active Directory at all, i have deployed additional domain controllers from each forest on each subscription.
    For example in subscription 1 we have additional domain controller of forest 1 and in subscription 2 we have additional domain controller of forest 2.
    Thanks
    If answer is helpful, please hit the green arrow on the left, or mark as answer. Salahuddin | Blogs:http://salahuddinkhatri.wordpress.com | MCITP Microsoft Lync

  • Domain Upgrade & Cross Forest Trusts

    Hi,
    I manage a single  windows 2003 Forest with a single domain (AD Level Windows 2003 R2). I'm preparing to upgrade the domain to Windows 2008 R2 but before I do I'm hoping someone can advise if this will impact on a number of cross forest trusts I have
    with related organisations. 
    The trusts are a mix of 1 way and 2 way non transitive domain level trusts. 
    My query is, will I need to recreate these trusts after and "adprep /forestprep" or "adprep/domainprep" (getting resources on the opposing side lined up to do create\recreate trusts is a big job so I'm hoping the impact with be zero).
    Thanks in advance
    Paul

    > if this will impact on a number of cross forest trusts
    No, it will not.
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Where to create cross-forest trust

    I need to create a cross-forest trust between DSfW and MS AD. I'm following the documentation at http://www.novell.com/documentation/...n.html#bfb58i5 but I got confused... Do I need to perform these steps on a workstation belonging to DSfW domain or AD domain? The text seems to indicate that these steps need to be done on DSfW domain, but the pictures seem to show AD domain.

    OK, confusion cleared. I created the trust on DSfW side, everything went smoothly. We can consider this thread closed.

  • I bought a new laptop and can access my itunes library but when i try to add purchased playlist songs to my ipod message appears asking if I'm ok with erasing all other songs on the ipod. Help needed.

    I bought a new laptop and can access my itunes library but when i try to add purchased playlist songs to my ipod message appears asking if I'm ok with erasing all other songs on the ipod. How do I add purchased playlist to ipod without erasing existing ipod playlists?

    cujoftw wrote:
    wow ... I get a headache just trying to read what you just said. I went and read how to migrate my library and found that you can only migrate purchased media.
    No, you can easily migrate your entire library from one working compter to another.
    If you fail to backup or migrate your library and find yourself with nothing but a new empty computer and a device full of content iTunes is designed to only recover the iTunes purchased content, however third party tools can help recover everything if needed.
    tt2

  • I need to update specific records(of variable lengths) in a file. I can get the correct record but when I update it(add info), it overwrites part of the record following it. I am using labview 6.0

    I need to update specific records(of variable lengths) in a file. I can get the correct record but when I update it(add or change info), it overwrites part of the record following it. I am using labview 6.0. I need to be able to insert information into the middle of a file without disturbing the data before and after

    It's hard to give more specifics without more detail, but in general you're going to need to read in the entire file, split it into three pieces (everything before the record of interest, the record itself, and everything after the record of interest), modify the record, reassemble the three pieces in proper order, and write the whole thing back to the file.Of course if the file is very large you might not want to actually implement it this way, but conceptually at least, this is what you are looking at.If this file some sort of proprietary format?Mike...PS: this type of issue is why I really like databases...
    Certified Professional Instructor
    Certified LabVIEW Architect
    LabVIEW Champion
    "... after all, He's not a tame lion..."
    Be thinking ahead and mark your dance card for NI Week 2015 now: TS 6139 - Object Oriented First Steps

  • When i try to download an app and i have entered my password i am asked to add some security questions. I can add two questions and an alternative e-mail address, however it will not let me select the third security question.

    when i try to download an app and i have entered my password i am asked to add three security questions. I can add two questions and an alternative e-mail address, however it will not let me select the third security question.

    Thanks Liam. After the second ap download it asked me three security questions on iTunes and on my MAC it allowed me to set up these with no error on the third question. iPAD 3 now downloads apps fine.
    Apple really need to sort out this issue or provide guidance on this. Two days of the unit not really being fit for purpose - what use is an IPAD without the ability to download aps.
    Also NO Response from Apple via online tech support and it's now been nearly 24 hours - I was told by telephone support I would get a response within 24 hours or less, as also stated in the email response too!??
    It would be good to get a formal response from Apple on this rather than radio silence.

Maybe you are looking for

  • Excel web access: Parameters in external data sources not supported???

    I have a SharePoint 2013 site with Excel services. The site itself has a Current User Filter Web Part which gives filter value [userID] to a Excel web access -web part. In the Excel itself I have a named area(UserIDfromSharePoint) defined as a parame

  • Help! web.xml security without using WAR files

    I'm currently using the RDBMSRealm and URL ACL security for my app. I would like to use the web.xml descriptor for security so that I can specify login pages and such. We currently are not using WAR files. I've been having alot of trouble setting thi

  • Help!!!! How do I get the CD Tray to open using Java

    Please I need some help.... A bit line of code that will open the CD tray for a windows OS. Cheers Rylan

  • Help!!! hard disc problem message 40gb zen ex

    My son purchased a Zen Extra 40 gb about 6 months ago and now will not operate. When trying to reboot, no matter what you try and do, harddisc problem message is displayed. What if any thing can we do? If it's something we can't fix ourselves, where

  • My Macbook won't start up...Please help!

    My Macbook powers on but doesn't go past the grey screen with the apple. The gear thing keeps turning but it doesn't start up. What can I do? I'm a bit technology challenged but I want to try everything before I take it in. I'm scared of losing all m