Article ID: 312373 - Last Review: October 30, 2006 - Revision: 2.2 Resultant Set of Policy Planning mode is not supported in cross-forest scenarios in Windows Server 2003This article was previously published under Q312373 SYMPTOMS Administrators cannot use the Resultant Set of Policy (RSoP) Planning mode to plan for scenarios that span forests in Microsoft Windows Server 2003. For example, you cannot plan a scenario where a user logs on to a workstation in Forest 1 from Forest 2. When you try to run RSoP Planning mode in a cross-forest environment, you may receive the following Group Policy error message: Cross forest planning mode scenarios are not currently supported CAUSEThis issue occurs because RSoP Planning mode does not support cross-forest scenarios because domain controllers are not well trusted outside their respective forests. In many potential scenarios, RSoP cannot validate the information that is returned from a domain controller that is located in another forest. The Authenticated Users group must have Read permissions on relevant policies to successfully read a particular policy in a cross-forest environment. Microsoft does not recommend granting Read permission for the Authenticated Users group to read all policies. If both the user and the computer reside in the same forest, RSoP will be able to generate a complete set of data. In a cross-forest scenario, if the user wants to connect to a computer that is in the remote forest to generate the RSoP Planning data for that user, the domain controller of the forest where the user is residing must first contact the domain controller of the remote forest. This is performed to obtain a list of policies that apply to the appropriate user or computer of the requested domain controller. The domain controller performs this action on behalf of the user who uses RSoP Planning. The results that are returned to the requested domain controller depend on the rights that the domain controller has in the remote forest instead of the user who uses RSoP planning. Therefore, cross-forest support is blocked in RSoP Planning mode because the data that is provided by RSoP Planning may be incomplete or inaccurate. Cross-forest support for RSoP Planning may be enabled in a future version of Windows. Consider the following scenarios. Collapse this table
WORKAROUNDTo work around this issue, you may run RSoP Planning mode on the domain controller of the user and the domain controller of the computer separately, and then manually combine the data to analyze the result. For additional information about how to install and use RSoP in Windows Server 2003, click the following article number to view the article in the Microsoft Knowledge Base: 323276
(http://support.microsoft.com/kb/323276/
)
How to install and use RSoP in Windows Server 2003
STATUS
This behavior is by design. MORE INFORMATIONFor additional information about RSoP, visit the following Microsoft Web site: http://technet2.microsoft.com/windowsserver/en/library/C145910B-CDFF-4563-BC78-9E53CC49DFDD1033.mspx
(http://technet2.microsoft.com/windowsserver/en/library/C145910B-CDFF-4563-BC78-9E53CC49DFDD1033.mspx)
| Article Translations
|
Back to the top
