Problems Changing Nested Global Group Scope to Universal Group (268277)
The information in this article applies to:
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Datacenter Server
This article was previously published under Q268277 SYMPTOMS
In the Active Directory Users and Computers tool, you can change a nested global group's scope to a universal group in Native mode. You should not do this because global groups can only contain users from the group's domain or other global groups in a Native-mode Windows 2000-based domain. This will cause ACEs from the parent global group not to be applied to users of the newly converted universal groups. This can cause issues with denied access and could allow unprivileged access to domain resources.
CAUSE
This behavior is caused by a problem in Samsrv.dll.
RESOLUTIONTo resolve this problem, obtain the latest service pack for Windows 2000. For additional information, click the following article number to view the article in the
Microsoft Knowledge Base:
260910 How to Obtain the Latest Windows 2000 Service Pack
The English version of this fix should have the following file attributes or later:
Date Time Version Size File name
--------------------------------------------------
07/27/00 07:32p 5.0.2195.2103 493,328 Lsasrv.dll
08/02/00 04:09p 5.0.2195.2103 906,000 Ntdsa.dll
08/09/00 02:30p 5.0.2195.2103 379,664 Samsrv.dll
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article. This problem was first corrected in Windows 2000 Service Pack 2.
Modification Type: | Minor | Last Reviewed: | 9/26/2005 |
---|
Keywords: | kbHotfixServer kbQFE kbbug kbfix kbWin2000PreSP2Fix KB268277 |
---|
|