Quantcast
Channel: Directory Services forum
Viewing all articles
Browse latest Browse all 31638

Login to SQL Server fails when user connects from another domain through group membership

$
0
0

Objects in use

Alpha.com (NetBIOS name: Alpha) Windows 2003 domain

Bravo.com (NetBIOS name: Bravo) Windows 2008 R2 domain

A two-way forest trust between Alpha and Bravo is established

A User Alpha\Alice

A Global Security Group in Alpha named GSG

A Domain Local Group in Bravo named DLG

 

Scenario:

Alpha\Alice is granted Alpha\GSG membership.

Alpha\GSG is granted Bravo\DLG membership.

Bravo\DLG is created as login in SQL Server and granted db_readonly in SomeDB.

 

Problem:

When Alpha\Alice tries to connect from her workstation in Alpha, the result is 18456.

First Workaround: Grant Bravo\DLG membership to Alpha\Alice.

Test connection from her workstation. Same result. Reverse the last change.

Second Workaround: Create Alpha\Alice as login in SQL Server.

Test connection from workstation: Succesful

 

Whenever membership is altered, the user logs out of workstation so the TGT is updated.

This is not related to nested AD groups, since direct membership of Bravo\DLG didn't yield another result.


Any ideas how to troubleshoot this?

Appreciate any advice


/Tonny


/torpo



Viewing all articles
Browse latest Browse all 31638

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>