• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 2207
  • Last Modified:

Forest Trust - Functional Levels

I plan to create a forest trust between an AD 2003 forest (2003 native mode) and 2008 R2 AD (2008 R2 functional level) - is this ok to do with the different levels or do I need to leave the 2008 in 2003 mode for the duration of the trust?

Also, is there any technical risk in creating trusts? Is anything likely to break? (other than security risks)
0
GeorgeFromTheBank
Asked:
GeorgeFromTheBank
  • 2
2 Solutions
 
ImaCircularSawTechnical LeadCommented:
These functional levels are compatible, you should have no issues.  Makes sure each server can see the other via DNS host name.  Use NSLOOKUP to test.

All the trust does is allow cross-domain authentication, it won't automatically authenticate, only allow you to search another domain for users and assign permissions to them in the trusted domain.  You cannot run 2008 FFL in a domain without any 2008 domain controllers (infact I think all of your DCs have to be 2008.

What are you going to be using the trust for?
0
 
Chev_PCNCommented:
You do not need to change the domain functional level at all - the trust will function across the forests.
There is no technical risk in creating a trust - you are simply making resources from one domain available in another. The only real risk (in my opinion) is managing the trusts going forward.
Do you have a resource sharing strategy in place?
Do you have a plan to work groups & group membership across trusts?
Are your DNS servers configured correctly?
0
 
GeorgeFromTheBankAuthor Commented:
Thanks for all your responses, very helpful.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now