Isolated forests - DMZ

Hi,
 We have an internal forest and an isolated perimeter DMZ forest.  There is no trust between the two forests. The Service Desk and Help Desk need the ability to administrate the resources in the perimeter DMZ forest on a limited basis.Can AD tools installed on a server joined to the internal forest be against domain controllers in the DMZ?   The primary reason is to deny them the ability to login locally and to have to put up a tools server in the DMZ.  They will have limited credentials to perform some resource administration.  
StrangeBrew2Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

RickSheikhCommented:
With no Trust, it is not possible. You can accomplish what you are after by adding an "admin server" to the DMZ forest with RSAT/adminpak and working out the required delegations for the helpdesk group.
0
StrangeBrew2Author Commented:
Sigh, I was afraid of that with native RSAT tools.   Have you had luck with 3rd party tools?
0
RickSheikhCommented:
No. I don't think a third party product can allow to go across to a different forest without a trust to update attributes and etc. FIM/ILM can potentially do this but it would be too much of an overhead for your need.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.