Summary: There may come a time when you need to convert your Global Groups into Universal Groups such as if you're in a multi-domain Forest. This is because the Global Catalog server does not have a copy of Global Groups in other domains. This can cause a problem with Distribution list expansion.
Tip: To bulk change your Global Security or Distribution Groups into Universal Groups; you can use Admodify using the custom attribute tab of "groupType"
Download Admodify:
ftp://ftp.microsoft.com/PSS/Tools/Exchange%20Support%20Tools/ADModify
1. Launch ADMODIFY.EXE
2. Click Modify Attributes
3. Domain List=Choose your Domain; Domain Controller=Choose your DC
4. Check only Groups; Check Advanced Features; Click Traverse Subcontainers
5. Click the Green Arrow and now highlight your Domain
6. Click Custom LDAP query.
Global Security Groups
(&(objectcategory=group)(grouptype:1.2.840.113556.1.4.803:=-2147483646))
7. Click Add to list and click OK
8. Select All and click next.
9. Click Custom Tab. Click Make a customized attribute modification
Attribute Name: groupType
Attribute Value: -2147483640
Click Ok. This will convert your Global Security Groups to Global Universal Groups.
Use the following Chart to convert your Global Distribution Groups.
[Group Scope] [Group Type] [groupType value] [sAMAccountType attribute]
[Universal] [Distribution] [8] [268435457]
[Universal] [Security] [-2147483640] [268435456]
[Global] [Distribution] [2] [268435457]
[Global] [Security] [-2147483646] [268435456]
[Domain Local] [Distribution] [4] [536870913]
[Domain Local] [Security] [-2147483644] [536870912]
James Chong (MVP)
MCITP | EMA; MCSE | M+, S+
Security+, Project+, ITIL
msexchangetips.blogspot.com
Tip: To bulk change your Global Security or Distribution Groups into Universal Groups; you can use Admodify using the custom attribute tab of "groupType"
Download Admodify:
ftp://ftp.microsoft.com/PSS/Tools/Exchange%20Support%20Tools/ADModify
1. Launch ADMODIFY.EXE
2. Click Modify Attributes
3. Domain List=Choose your Domain; Domain Controller=Choose your DC
4. Check only Groups; Check Advanced Features; Click Traverse Subcontainers
5. Click the Green Arrow and now highlight your Domain
6. Click Custom LDAP query.
Global Security Groups
(&(objectcategory=group)(grouptype:1.2.840.113556.1.4.803:=-2147483646))
7. Click Add to list and click OK
8. Select All and click next.
9. Click Custom Tab. Click Make a customized attribute modification
Attribute Name: groupType
Attribute Value: -2147483640
Click Ok. This will convert your Global Security Groups to Global Universal Groups.
Use the following Chart to convert your Global Distribution Groups.
[Group Scope] [Group Type] [groupType value] [sAMAccountType attribute]
[Universal] [Distribution] [8] [268435457]
[Universal] [Security] [-2147483640] [268435456]
[Global] [Distribution] [2] [268435457]
[Global] [Security] [-2147483646] [268435456]
[Domain Local] [Distribution] [4] [536870913]
[Domain Local] [Security] [-2147483644] [536870912]
James Chong (MVP)
MCITP | EMA; MCSE | M+, S+
Security+, Project+, ITIL
msexchangetips.blogspot.com