Looking for answers on Two Way Trust Vulnerabilities

I'm trying to put together a point paper explaining the benefits and the vulnerabilities of establishing a two way trust between two domains.  I've got plenty of information on the benefits but honestly I can't find anything "negative" towards establishing one.  Can anyone explain some of the inherent vulnerabilities of establishing a trust?  Users from domain A cannot access resources from domain B unless the permissions allow the specific user, authenticated users or everyone to access that resource.  Administrators from domain A should not be able to do any administration in domain B.  
The next question, what are some of the things I should do security wise to "protect" my network more once I establish a two way trust?
LVL 1
tej071Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

deroodeSystems AdministratorCommented:
The name "Trust" says it all.

The admin of Domain B will have to trust the domain admins of domain A. In practice, permissions aren't assigned to specific users but to groups. If a domain admin A adds member "criminal" to a group which has full rights in "financial data" on domain B that is not visible.
0
tej071Author Commented:
deroode,
Are you sure about the admins from one domain having rights on the other domain?  I ask this because an administrator in a child domain does not have rights to make changes to a parent domain and that is a transitive trust.  I understand users will have access to resources on the other domain but only if that is specifically set, they just dont' get access to resources just because a trust was established.
0
deroodeSystems AdministratorCommented:
No, that was not wat i said.

If Domain admin B gives folder permissions to  a group from Domain A, he cannot see who is in the Domain A Group. The Domain admin from domain A however can put anyone from Domain A in that group.

Domain admin B cannot see that Domain admin A has added someone to the group, to him it's just the same group.
0
tej071Author Commented:
Correct, I misread your original statement and the same is true WITHIN Domain A when I assign users to a resource with full rights from Domain A to resources in Domain A I trust that they won't cause trouble there as well.  
I guess my question was more geared toward Administrators from one domain being able to influence things in another domain once the trust is established.  Without assigning them any special rights they have no more abilities to make changes in my domain than a user on my domain has rights (i.e. adding user accounts, changing FSMO roles, changing SMTP connectors, etc), correct?

0
deroodeSystems AdministratorCommented:
Yes, that is correct.

I cannot help you with your second (security) question, sorry..
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.