# Trouble adding a group from a root domain to a newly created user object in a child domain

**URL:** <https://forums.powershell.org/t/trouble-adding-a-group-from-a-root-domain-to-a-newly-created-user-object-in-a-child-domain/19303>\
**Category:** PowerShell Help\
**Created:** [May 12, 2022, 6:12pm UTC](https://forums.powershell.org/t/trouble-adding-a-group-from-a-root-domain-to-a-newly-created-user-object-in-a-child-domain/19303 "2022-05-12T18:12:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raymond\_Overman](https://avatars.discourse-cdn.com/v4/letter/r/9f8e36/32.png) [@Raymond\_Overman](https://forums.powershell.org/u/Raymond_Overman)\
**Post date:** [May 12, 2022, 6:12pm UTC](https://forums.powershell.org/t/trouble-adding-a-group-from-a-root-domain-to-a-newly-created-user-object-in-a-child-domain/19303/1 "2022-05-12T18:12:41Z")

</div>

I have an AD environment with a root and two child domains. I need to add groups that live in the root domain to a newly created user object no matter which domain it’s created in. After creating the object, I check to see if it’s in the global catalog and if not, I sync the object. I then have a function that checks the replication and waits until it’s found. It doesn’t seem to sync in a reasonable amount of time. Can someone give me an idea why?

```auto
Function Get-UserReplication {
    [cmdletbinding()]
    Param (
        [string]$DistinguishedName,
        [string]$Server
    )
    
    Do{
            try {
                $NewUser = get-aduser -Server $Server -Filter {DistinguishedName -eq $DistinguishedName}
            }catch{
                Write-Verbose "Waiting for replication."
                Start-sleep -Seconds 30
            }
    } While (!$NewUser)

    Return $True
}

#
# Other stuff that reads a JSON file from PowerAutomate with new employee information and creates the object.
# This works and then I try to wait for it to finish replicating.
#

# If not in root domain sync new user object to root domain
If ($UserDomain -ne $RootDomain) {
    
    Get-ADUser -Identity $NewUserObject.samAccountName | Sync-ADObject -Destination $RootDomainGC

    Get-UserReplication -DistinguishedName $NewUserObject.DistinguishedName -Server $GCLookup

}

# Add user object to licensing groups
$Licenses = $NewUserObject.licenses.Value

foreach ($License in $Licenses) {
    Write-Verbose "Adding new user to $License."
    Add-ADGroupMember -Server $RootDomain -Identity $license -Members $newUserObject
}

```

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:17pm UTC](https://forums.powershell.org/t/trouble-adding-a-group-from-a-root-domain-to-a-newly-created-user-object-in-a-child-domain/19303/2 "2024-05-16T20:17:57Z")

</div>


