Member server 2019 cannot add user account from Trusted domain

Arnold Mishaev 71 Reputation points
2022-05-23T19:16:52.13+00:00

Hi everybody,

we're in the middle of migration project to migrate all objects from Domain A to Domain B, right now we are trying to migrate "security translation".
and we're facing with issue when we trying to add administrator account from trusted domain B, to a member server in domain A, see the screenshot below
204738-image.png

We're successfully managed to add the administrator account from Domain B to local administrator groups in all member server in Domain A, except one server

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,453 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,113 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,843 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Limitless Technology 43,931 Reputation points
    2022-05-26T07:43:00.277+00:00

    Hello

    Thank you for your question and reaching out. I can understand you are having issues related to adding users to Group from Domain A to Domain B,

    The error message "A member could not be added to or removed from the local group because the member does not exist" is generic Windows error. When I search online, I found that this error could occurs when there is duplicate SID in computer OS. I found ntdsUtil tool to find and clean up duplicate SID.

    https://learn.microsoft.com/en-US/troubleshoot/windows-server/identity/ntdsutil-find-clean-duplicate-security-identifiers

    --------------------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--


  2. rr-4098 1,176 Reputation points
    2022-05-26T17:21:11.367+00:00

    You are using a two-way trust correct?


  3. rr-4098 1,176 Reputation points
    2022-05-29T08:40:24.597+00:00

    Is it possible it could be duplicate SID's as suggest in the following article?

    https://learn.microsoft.com/en-us/answers/questions/40034/ad-connect-setup-a-member-could-not-be-added-to-or.html

    0 comments No comments