AD Migration question: Can Active Directory Native Mode still Trust NT 4 domains.

Posted on 2005-05-11
Last Modified: 2008-03-10
We are in the middle of doing our migration to AD from a NT4 domain structure. We have an NT 4 account domain and multiple NT resource domain. We want to use SID history but our AD is in mixed mode right now. Our engineers are saying that you can't put the AD in native mode because they will no longer be able to established trust with the NT 4 resource domains. Since we can't totally get rid of the trusts during our migration we are forced to stay in mixed mode and therefore lose the benefit of SID history. We have a consultant now saying we can still have the trust but since our engineers have already tried it and put it into production, we do not want to go back and risk losing the trusts again. Anyone have any experience during their migration
Question by:kriggins14
    LVL 18

    Accepted Solution

    My domain is in native mode and I have a one way trust with an NT 4 domain without any problems. My users authenticate in the NT 4 domain with no problems.

    Also see this EE PAQ which provides some good information and also states you CAN do this.
    LVL 9

    Expert Comment

    As you see from this post it is possible with trusts to NT4 domains. What your engineers should have said is that you can not have NT4 DC's in a w2k or w2k3 domain in native mode

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Do You Know the 4 Main Threat Actor Types?

    Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

    Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
    Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
    how to add IIS SMTP to handle application/Scanner relays into office 365.
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    21 Experts available now in Live!

    Get 1:1 Help Now