Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Forest Trust - Functional Levels

Posted on 2011-03-07
4
Medium Priority
?
2,194 Views
Last Modified: 2012-05-11
I plan to create a forest trust between an AD 2003 forest (2003 native mode) and 2008 R2 AD (2008 R2 functional level) - is this ok to do with the different levels or do I need to leave the 2008 in 2003 mode for the duration of the trust?

Also, is there any technical risk in creating trusts? Is anything likely to break? (other than security risks)
0
Comment
Question by:GeorgeFromTheBank
  • 2
4 Comments
 
LVL 10

Assisted Solution

by:ImaCircularSaw
ImaCircularSaw earned 80 total points
ID: 35054917
These functional levels are compatible, you should have no issues.  Makes sure each server can see the other via DNS host name.  Use NSLOOKUP to test.

All the trust does is allow cross-domain authentication, it won't automatically authenticate, only allow you to search another domain for users and assign permissions to them in the trusted domain.  You cannot run 2008 FFL in a domain without any 2008 domain controllers (infact I think all of your DCs have to be 2008.

What are you going to be using the trust for?
0
 
LVL 9

Accepted Solution

by:
Chev_PCN earned 120 total points
ID: 35054952
You do not need to change the domain functional level at all - the trust will function across the forests.
There is no technical risk in creating a trust - you are simply making resources from one domain available in another. The only real risk (in my opinion) is managing the trusts going forward.
Do you have a resource sharing strategy in place?
Do you have a plan to work groups & group membership across trusts?
Are your DNS servers configured correctly?
0
 
LVL 9

Expert Comment

by:Chev_PCN
ID: 35055085
0
 

Author Comment

by:GeorgeFromTheBank
ID: 35055262
Thanks for all your responses, very helpful.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
Scripts are great for performing batch jobs against users, however sometimes the GUI is all you need.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question