Site icon EfmSoft

What does NTSTATUS 0xC00002D6 (STATUS_DS_NO_NEST_LOCALGROUP_IN_MIXEDDOMAIN) mean?

 
Previous Next
STATUS_DS_NO_NEST_GLOBALGROUP_IN_MIXEDDOMAIN STATUS_DS_GLOBAL_CANT_HAVE_LOCAL_MEMBER

STATUS_DS_NO_NEST_LOCALGROUP_IN_MIXEDDOMAIN

Meaning and context of STATUS_DS_NO_NEST_LOCALGROUP_IN_MIXEDDOMAIN

The rejected member is another Domain Local group, and the domain is using the legacy mixed-mode nesting rules. In this mode, a Domain Local group can contain global groups and accounts, but it cannot contain another Domain Local group.

Verify both objects rather than relying on their display names: inspect each group’s scope, the domain that owns it, and whether the request is changing membership on a security or distribution group. A same-name group from another domain is especially easy to misread in administrative tools.

For a modern design, first determine whether the domain configuration is intentionally legacy. Native-mode rules still do not allow a Domain Local group to contain a Domain Local group from another domain or forest, so raising the mode would not make every cross-domain nesting request valid.

Mixed-mode nesting rules | Native-mode nesting rules | AD DS group-type glossary

Native status interpretation

STATUS_DS_NO_NEST_LOCALGROUP_IN_MIXEDDOMAIN is 0xC00002D6, an NTSTATUS error value. AllStat describes it as “In mixed domain, cannot nest local groups with other local groups, if the group is security enabled.”


Looking for a different code? Search another status or error code.

Exit mobile version