Logon scripts do not run across domains
Hello,I have the following configuration:1 Forest2 domains (non-contiguous), in 2 locations.I am able to logon to either domain with users from either domain in each location.Logon scripts in each domain work if the user in the domain logs on within that domain.A user in domain1 can logon to domain2 - however their logon script will not run.It appears to be an IE security problem as if I attempt to run the script manually from a machine in domain1 from the netlogon in domain2 I am presented with the 'open file' security dialog box.My question is how can allow this 'trust' to be instigated - I thought domains in a single forest intrinsically trusted one another.Thanks very much.
August 29th, 2007 4:18pm
Domains do 'trust' each other - but that does not mean that everyone has access to anything....aDomain is a security boundry. You still need to specify which resources in each domain that the security principles have access to.
It doesnt sound like an IE security problem here, but permission to the trusted domain's sysvol directory (or other share)where the scripts reside.
Ward
Free Windows Admin Tool Kit Click here and download it now
September 4th, 2007 6:22pm


