Error: 'Access is Denied' when trying to access a resource that has foreign Domain Local groups list (NETIQKB54216)

  • 7754216
  • 02-Feb-2007
  • 30-May-2007


Domain Migration Administrator 7.x

Error: 'Access is Denied' when trying to access a resource that has foreign Domain Local groups listed as ACEs on the resource.

Native tools will not allow me to add a Domain Local group onto a resource in a different domain but Domain Migration Administrator will add the Domain Local group to a resource in a different domain when running the Security Translation for Domain Local groups.


The issue is caused by the following scenario:

  • A Domain Local group contains user accounts from its local domain as members.
  • The Domain Local group is migrated.
  • The member user accounts are migrated.
  • Security Translation is performed for the migrated Domain Local groups on the source computer accounts that have them listed as ACEs on resources.
  • Once Security Translation is finished, user accounts that are members of the Domain Local groups get 'Access is Denied' error when trying to access the resource.

This issue is caused by a limitation of Microsoft group membership properties and security boundaries.  Native tools will not allow you to add a Domain Local group as an ACE to a resource when that resource is located in a different domain than where the group originates.


To resolve this issue:

  1. Re-structure your group membership according to Microsoft best practices. For example, put user accounts into Global groups, put Global groups into Local groups, and then use the Local group to set permissions on the resource.
  2. Manually add the user account permissions to the resource.
  3. Migrate the computer account that hosts the resource.

When translating security for Domain Local groups in Add mode, Domain Migration Administrator (DMA) adds the Domain Local group's ACE to resources in the source domain.  DMA does this so that when and if the computer account gets migrated, the Access Control Lists on the resources will be updated with the correct, migrated Domain Local group's Access Control Entries.

Additional Information

Formerly known as NETIQKB54216