Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Exchange connection across domain trust

Posted on 2010-09-15
7
Medium Priority
?
782 Views
Last Modified: 2012-05-10
We have an existing 2003 exchange environment and when we went to upgrade we found out our config is not supported.

So we built a new domain (domain2) and built a 2010 exchange environment with a mailbox server, a hub transport, and a CAS.  Everything works great from outside the network.  We set up a two way trust between domain1 and domain 2

The issue is when a user in domain1 tries to connect to the new exchange server.  It gives a variety of different issues.  We have tried to connect Outlook to the AD server instead of the CAS, and that sometimes will work for the name resolution, but then Outlook crashes later.  It seems to be related to accessing the address list.

If we log into the exact same machine as a local user (no domain) it works just like it does from outside.

There is a hotfix from MS that is supposed to deal with a lot of 2010 issues, but I wanted to see if there was something with the trust that may be causing this issue.
0
Comment
Question by:TacoFlavoredKisses
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 42

Expert Comment

by:Adam Brown
ID: 33684715
Are both domains in the same forest? Exchange tends to be a little finicky when there are two organizations in the same forest.
0
 
LVL 1

Author Comment

by:TacoFlavoredKisses
ID: 33702366
Sorry for the delay.  They are in separate forests.
0
 
LVL 42

Accepted Solution

by:
Adam Brown earned 2000 total points
ID: 33702937
Okay. It's even worse when you've going from forest to forest. Usually you need a go-between product to handle authentication for Exchange between forests. Microsoft's Identity LifeCycle Manager (ILM) is built to handle that type of situation. The big issue is that Exchange doesn't properly communicate authentication information for users across a trust link. Trusts in general only provide SID translation between forests and Exchange needs a little more than that to work properly.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 1

Author Comment

by:TacoFlavoredKisses
ID: 33703713
That is too bad.

If we were to make the trust one way only and not trust domain a in domain b would this resolve the issue and now appear as a non trusted user?
0
 
LVL 42

Expert Comment

by:Adam Brown
ID: 33703784
Possibly. They would be required to enter credentials in the other domain, though. Without the trust, there's no way for them to be authenticated in the other domain, so they have to have a usable account in that domain to do anything in it. Trusts allow you to access most things in domain b using an account located in domain a. However, Exchange can't read or recognize the user in domain a properly, so you would need to create a user in domain b for that user to have access to the domain b exchange features, which is how you would handle authentication between domains without a trust. The problem is that you lose the single sign on capabilities. The user in domain a will have to enter credentials for domain b any time they try to access resources in that domain. Make sense?
0
 
LVL 1

Author Comment

by:TacoFlavoredKisses
ID: 33704401
Makes perfect sense.  Unless there is another way we aren't thinking of this seems like the best option.  So I will have them use accounts for domain b when launching outlook in domain a until we can fully migrate all the network components to the new domain.
0
 
LVL 1

Author Comment

by:TacoFlavoredKisses
ID: 33729528
Did not try to refund, but yet it is trying that.  Trying to object.
0

Featured Post

Veeam Task Manager for Hyper-V

Task Manager for Hyper-V provides critical information that allows you to monitor Hyper-V performance by displaying real-time views of CPU and memory at the individual VM-level, so you can quickly identify which VMs are using host resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question