Local group membership is not updated after translating security on a BDC. (NETIQKB22123)

  • 7722123
  • 02-Feb-2007
  • 01-Jun-2007


Domain Migration Administrator 7.x

Local group membership is not updated after translating security on a BDC. 

NTFS and share ACL's are updated but the local group membership is not after translating security on a BDC.

This is because a BDC is not writable.  The membership of domain local groups is controlled by the domain SAM, which is only writable on the PDC of an NT 4 domain.


Translate security for local groups on the PDC. 

To accomplish this:

  1. Run the Translate Security Settings wizard.
  2. Select the NT user accounts and global groups that are members of the NT domain local groups.
  3. Select the PDC.
  4. Select the Local groups checkbox.
  5. Complete the wizard. 

The standard Windows NT replication process will replicate the SAM information from the PDC to the BDC.

Additional Information

Formerly known as NETIQKB22123