Unable to add user from child domain

MamadouCoulibali-4946 486 Reputation points
2024-03-27T14:57:30.6366667+00:00

I am trying to add a user from a child domain to a group in the root domain, but I am receiving this error:

The specified user was not found. If the user exists on another active directory Domain controller in the enterprise, it may take 15 minutes or more for the user to be replicated to the global catalog
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,860 questions
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 32,511 Reputation points
    2024-03-27T21:01:10.6766667+00:00

    Hi @MamadouCoulibali-4946

    Did you check replication and active directory health using the following command:

    repadmin /showrepl
    dcdiag
    

    Did you try to disable and enable global catalog on domain controller in root domain ?

    Check if you have the same issue when Global catalog is unchecked in root domain.


    Please don't forget to accept helpful answer

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Marcin Policht 10,675 Reputation points MVP
    2024-03-27T15:35:39.8966667+00:00

    Make sure that the group scope is either domain local or universal. It cannot be domain global - if it is, convert it to either of the other two.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin


  2. Daisy Zhou 18,701 Reputation points Microsoft Vendor
    2024-03-28T02:30:54.46+00:00

    Hello MamadouCoulibali-4946,

    Thank you for posting in Q%A forum.

    1.Please check if this user is actually in child domain.

    2.Please check AD replication on PDC in the root domain.

    repadmin /showrepl >C:\rep1.txt

    repadmin /replsum >C:\rep2.txt

    repadmin /showrepl * /csv >c:\repsum.csv

    3.Force the entire AD forest to replicate and check if you can perform the same operation.

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments