Active directory Trusts restrict other side Domain Admins

I have one Domain Fred.com

And the company is merging with another Jane.com

jane.com has lots of domain admins.(which Fred.com can’t trust)

I need to share resources and keep the security that Fred.com has, I’ve read on MS TechNet
"Domain administrators of any domain in the forest have the potential to take ownership and modify any information in the Configuration container of Active Directory. These changes will be available and replicate to all domain controllers in the forest. Therefore, for any domain that is joined to the forest, you must consider that the domain administrator of that domain is trusted as an equal to any other domain administrator."
http://technet.microsoft.com/en-us/library/cc961481.aspx
and this worries me as Fred.com is a secured Domain and although in the future all of jane.com’s users and computers will be migrated to Fred.com I still need to preserve security until Jane.com is removed

What are my options?


Thanks

Mike
MikeEddAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Vinchenzo-the-SecondCommented:
Create an external trust.  Domain admins in domain A will need be given permission in domain B to access resources, and vice versa
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
terrygreensillCommented:
I would look at selective authentication on a forest trust as described here http://technet.microsoft.com/en-us/library/cc758152(WS.10).aspx
0
Vinchenzo-the-SecondCommented:
Selective authentication is an option, but do remember u have set acls on the computer object itself before u configure any other security
0
MikeEddAuthor Commented:
So with an external trust domain admins don't have access to the AD in an administrative role on the other domain?

Mike
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.