ProblemConsider the following scenario:
- Multiple domains in separate forests are used, with a two-way forest trust in place.
- Both domains (e.g. Domain A and Domain B) have been configured in Directory Services.
- The RES ONE Workspace Console is used on a machine in Domain A.
- The Access Control on an application is given to a Domain Local Security Group in Domain A.
- Users from Domain B are added directly to this Domain Local Security Group in Domain A.
SolutionConfigure a Global Security Group in Domain B and add this group to the Domain Local Security Group in Domain A.
This is in accordance to Microsoft's best practice for Group Nesting.