    i have a windows 2003 forest and a windows 2000 forest and i created a two
    trust between the two forest which is external but i am having problems
    adding the global group in the win 2000 forest domain to a local group in the
    2003 forest domain. i can browse the local groups on the 2003 forest from the
    2000forest but when i try to add the gobal group to the local group on 2003
    forest the is a permission issue saying i don't have the rights.And from the
    2003forest i cannot browse the users in the 2000forest it gives a blank
    screen saying server is not available. i have also verified the trust in
    both directions with the same users and password which is created in both
    forest and it confirms success of the trust.Also the win2000 domain is in
    native mode and the win2003 domain is in 2000/2003 native mode.i have the
    everyone as member of thr Pre-Windows group. i also have WINS on both dc
    replicating and have DNS on both DCS configured and made secondary zones on
    each other.and i still get the message the server is not operational when i
    try to browse the win2000 forest and even though i can browse the win2003
    forest from the 2000forest when i try to join the domain admin group to the
    administrators group of the 2003forest i get the message you donot have the
    permission to modify the properties of this account.
    Please can any one help me with what i could be doing wrong.
    slawal, Nov 1, 2004
  2. Danilo Bordini [MVP], Nov 1, 2004
    the resolution is working fine from both servers because i can ping -a and it
    gives me the fully qualified names for the servers in both directions but i
    just pulled up the link you sent and found that i was still runniing service
    pack 3 on the 2000 box in the 2000forest so i am going to upgrade that and
    recreate the trust

    slawal, Nov 1, 2004
    Did you get this to work? I am trying to create a new Windows 2003 forest
    that will trust our existiing Windows 2000 forest. This needs to be a one
    way trust - Window 2003 forest trusts Windows 2000, not the other way
    around. What I have read is confusing me.

    Brett, Nov 4, 2004
