Unable to Bring Up the User List from a Windows NT 4.0 Trusted Domain on a Windows 2000-Based Server (291684)



The information in this article applies to:

  • Microsoft Windows 2000 Server SP1
  • Microsoft Windows 2000 Advanced Server SP1
  • Microsoft Windows 2000 Professional SP1

This article was previously published under Q291684

SUMMARY

When you attempt to add users from a Microsoft Windows NT 4.0 trusted domain to a local group on a Windows 2000-based member server that is a member of a Windows NT 4.0 domain, you may receive the following error message even though Windows NT 4.0-based computers in the same domain are able to bring up the list:
The specified domain does not exist.

MORE INFORMATION

In Windows NT 4.0, member servers that attempt to assign trusted domain entities to shared resources, contact the domain controller with which they have a secure channel to obtain the entity lists of the trusted domain. The domain controller that owns the secure channel in turn contacts a domain controller in the trusted domain for the list of entities. In Windows 2000, this behavior has changed slightly. The initial verification of the domain trust is performed by means of the secure channel (as has been performed in a Windows NT 4.0 environment).

The actual entity list, however, is obtained directly by the Windows 2000-based server that requests the list from the primary domain controller (PDC) of the trusted domain. The Windows 2000-based computer that requests the list of entities must be able to resolve and contact the PDC in the trusted domain. This requirement means that the Windows 2000-based computer must be able to use NetBIOS name resolution to resolve the NetBIOS 0x1B for the trusted domain which points to the PDC. Some methods of NetBIOS name resolution use the Windows Internet Name Service (WINS) and Lmhosts files.

In addition to the name resolution that is required, the correct trust relationship must enable the Windows 2000-based computer to make a computer account-authenticated connection to the PDC of the trusted domain as Windows 2000 cannot create a null session to the trusted domain.

For additional information, click the article numbers below to view the articles in the Microsoft Knowledge Base:

163409 NetBIOS Suffixes (16th Character of the NetBIOS Name)

180094 How to Write an Lmhosts File for Domain Validation and Other Name Resolution Issues


Modification Type:MinorLast Reviewed:1/27/2006
Keywords:kbinfo kbTrusts w2000trusts KB291684