Solved

Forest Trust - Functional Levels

Posted on 2011-03-07
4
2,153 Views
Last Modified: 2012-05-11
I plan to create a forest trust between an AD 2003 forest (2003 native mode) and 2008 R2 AD (2008 R2 functional level) - is this ok to do with the different levels or do I need to leave the 2008 in 2003 mode for the duration of the trust?

Also, is there any technical risk in creating trusts? Is anything likely to break? (other than security risks)
0
Comment
Question by:GeorgeFromTheBank
  • 2
4 Comments
 
LVL 10

Assisted Solution

by:ImaCircularSaw
ImaCircularSaw earned 20 total points
ID: 35054917
These functional levels are compatible, you should have no issues.  Makes sure each server can see the other via DNS host name.  Use NSLOOKUP to test.

All the trust does is allow cross-domain authentication, it won't automatically authenticate, only allow you to search another domain for users and assign permissions to them in the trusted domain.  You cannot run 2008 FFL in a domain without any 2008 domain controllers (infact I think all of your DCs have to be 2008.

What are you going to be using the trust for?
0
 
LVL 9

Accepted Solution

by:
Chev_PCN earned 30 total points
ID: 35054952
You do not need to change the domain functional level at all - the trust will function across the forests.
There is no technical risk in creating a trust - you are simply making resources from one domain available in another. The only real risk (in my opinion) is managing the trusts going forward.
Do you have a resource sharing strategy in place?
Do you have a plan to work groups & group membership across trusts?
Are your DNS servers configured correctly?
0
 
LVL 9

Expert Comment

by:Chev_PCN
ID: 35055085
0
 

Author Comment

by:GeorgeFromTheBank
ID: 35055262
Thanks for all your responses, very helpful.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ACTIVE DIRECTORY, EXCHANGE 11 106
Powershell to query AD 3 34
Installing Exchange 2016 2 24
AD and SQL Server 2016 2 25
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

791 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question