Solved

Tree root trust - Access Denied

Posted on 2010-09-17
3
901 Views
Last Modified: 2012-05-10
Hi all,

Building a new AD network I've setup a forest: alpha.forest and the tree root domain beta.local so all the users will log on to the domain 'beta'.

The automatic trust between them is only one way; if I validate the trust on Alpha it's fine.  If I validate the trust on Beta if fails with access denied.  I then log in with Alpha's admin credentials and I'm told it's all good.  I then retry the test and if fails again.

Can't see any errors in either event log at all.

Any advice most welcome.

Thanks
Paul.
0
Comment
Question by:looops
  • 2
3 Comments
 
LVL 24

Accepted Solution

by:
Mike Thomas earned 250 total points
ID: 33700692
"alpha.forest and the tree root domain beta.local"

Trust issues aside I do not quite understand what you have done? why build 2 forrests?

the whole point of having a forrest is that you can have a single security boundry with many domains.

so you should have a root domain

root.local then maybe a child domain called alpha which would be alpha.root.local or whatever.




0
 

Author Comment

by:looops
ID: 33701230
It's not two forests, it's a child domain but we wanted it's own name for branding / locale reasons. ie wanted the users to log into 'beta'.
0
 

Author Closing Comment

by:looops
ID: 33796881
I rebuilt the AD ito a standard 1st Forest / Domain.

Thanks for the input.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
Scenario:  You do full backups to a internal hard drive in either product (SBS or Server 2008).  All goes well for a very long time.  One day, backups begin to fail with a message that the disk is full.  Your disk contains many, many more backups th…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question