Single Distribution Group showing different different permission in two AD network
Hi,
i am having two domain controller with two way transative trust relation & when i am editing effective permission for same DL than i am see that on one domain controller user having only read only rigths but when on another domain controller than i see
that user is having full access permission on same dl
any one can help me to short out this issue
July 19th, 2010 1:12pm
On Mon, 19 Jul 2010 10:12:01 +0000, Luv2Microsoft wrote:
>i am having two domain controller with two way transative trust relation & when i am editing effective permission for same DL than i am see that on one domain controller user having only read only rigths but when on another domain controller than i see
that user is having full access permission on same dl
Within the same AD forest?
>any one can help me to short out this issue
Assuming you've waited long enough for AD replication to complete, I'd
say you had a problem with AD replication. If that's the case you
should move your question to a forum that specializes in AD (or just
in the general O/S). Exchange just uses the information in the AD, it
doesn't manage the AD.
---
Rich Matheisen
MCSE+I, Exchange MVP
--- Rich Matheisen MCSE+I, Exchange MVP
Free Windows Admin Tool Kit Click here and download it now
July 20th, 2010 5:28am
dear rich this is not problem of ad replication i think bcz ad replication going well......
July 20th, 2010 3:26pm
On Tue, 20 Jul 2010 12:26:30 +0000, Luv2Microsoft wrote:
>dear rich this is not problem of ad replication i think bcz ad replication going well......
You're entitled to your opinion, but if AD replication was working
then the permissions would be the same on every DC in the domain.
While you may see a copy of the object in a GC in some other domain,
the only writable copy is in the DCs of the domain in which the object
resides.
---
Rich Matheisen
MCSE+I, Exchange MVP
--- Rich Matheisen MCSE+I, Exchange MVP
Free Windows Admin Tool Kit Click here and download it now
July 21st, 2010 5:06am
its cause of accounts operator group because in one forest thats domain user group was inside in account operator........
August 6th, 2010 6:37am