humbletech99 Posted November 10, 2006 Report Share Posted November 10, 2006 I've got a domain trust between an NT4 domain and a 2003 AD domain while I migrate the desktops from the NT to the 2003 domain in batches. I would like to be able to prevent people from logging in to the old domain by accident which is available in the drop down box at the login prompt. It would be quite an easy thing to log on to the old domain by accident, and there are only 2 letter different between the old and new domains.How can I stop people from logging on to the old domain on a machine that is a member of the new active directory domain? Google hasn't turned up anything yet. Is there some GPO or something for this? I really really really don't want to go around disabling account by account because the old nt controller is crippling slow and almost impossible to administer now. Quote Link to comment Share on other sites More sharing options...
vinayak Posted November 13, 2006 Report Share Posted November 13, 2006 this seems to little critical, try only one way trust from NT to windows 2003 and no transitive. Quote Link to comment Share on other sites More sharing options...
humbletech99 Posted November 13, 2006 Author Report Share Posted November 13, 2006 Breaking the trust into one way like this would stop domain migration of the rest of the machines though, so can't do that.I've tried to do this via gpo, but I migrated sid history and since sids are used for this it denies the new domain users from logging on as well! Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.