How do i delegate domain admin to cross forest account.

Kevin 0 Reputation points
2023-11-09T13:34:22.44+00:00

Hi,

I currently have a setup involving two domains. In Domain 1, there is a Domain Controller (DC) and a Gateway (GW) configured for Windows Admin Center. A two-way forest-wide trust has been established between these two domains. My objective is to manage the Active Directory (AD) of Domain 2 using my account from Domain 1 within Windows Admin Center.

To achieve this, I have attempted to add myself to the "builtin\administrators" group in Domain 2, but unfortunately, I am unable to access the AD from the Admin Center. Surprisingly, when I use a Domain 2 admin account to log in from the Admin Center, it works perfectly. Additionally, I tried granting myself the "Enterprise Admin" role, but that did not yield the desired results either.

I'm encountering an issue where I cannot add my Domain 1 account to the Domain 2 "domain admins" group because Domain 1 does not appear in the available locations when I attempt to perform this action. I know that i cant add cross domain users to a global group. Can anyone provide insight into the specific rights or permissions that I may be missing to resolve this situation?

Your assistance and expertise would be greatly appreciated.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,451 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,091 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 20,461 Reputation points Microsoft Vendor
    2023-11-15T06:17:45.98+00:00

    Hello Kevin,

    Thank you for posting in Q&A forum.

    Please validate the forest trust on both domain and check if you can validate the forest trust successfully.

    Properties\Validate\type the credential and check the result. The information below is validated successfully.
    User's image

    If you cannot validate the trust successfully, you can try to recreate the two-way forest forest.

    Hope the information above is helpful.

    Best Regards,
    Daisy Zhou