We have a one way forest trust Forest A and Forest B, have created the Universal group and added the members in Forest A. Then added this to a Domain Local group in Forest B.
We want (certain) users from Forest A to be able to manage group policies on Forest B.
We've Delegated the Local Group rights to Edit a GPO but whenever we try to Edit it (even though the option is available) we get the error: "Failed to open the group policy object. You may not have the appropriate rights. Network access is denied"
Any ideas what this could be?
The "network access is denied" part of the error is throwing me as well. Doesn't give any further info on this.
Might be something simple that we've missed but if so we must keep missing it :) !
Any help appreciated!