I am trying to setup a new AD forest on Win2K3. We have an existing Win2K AD forest that I'm trying to setup a trust between. On the Win2K side, I can go in and add the Domain Admins group from the trusted domain and it works. I can open ADUC back up and still see the normal names for the trusted group in the Win2K administrators group. When I do the same thing on the Win2K3 forest, I can add the Win2K domain admins to the administrators group. When I open ADUC again and look at memebers, the Win2K users/groups added show up as CN=S.... What is going on. Ultimately, I am going to move users and computers out of the old forest to the new one to correct many bad setups from the contractors that set this up years ago before me. Any help would be appreciated.