A part of our division is creating a new forest and becoming an independent entity. Migration tools will need to be used to export objects out of our existing AD into their new forest root PDC. I need to give them the ability to export out of my AD server into their new forest without giving them the ability to modify my existing AD infrastructure.
My question is this:
Based on my knowledge and research it appears that One Way, Incoming External Trust using Selective Authentication is what I need. Please let me know if this is not the case.
Start Free Trial