NT trust relationship - Urgent!!!!

Posted on 2011-10-27
Last Modified: 2012-05-12
Hi Experts,
I have an emergency situation. It is kind of long story. I had a NT (PDC and BDC) domain and 2003 (three ADs) domain and Two ways trust relationship worked fine. When I have to upgrade the 2003 AD to 2008 R2 AD - I just added three more 2008 R2 servsers while 2003 ADs still up and running, I knew the trust relationship won't work so I upgrade NT to 2003 AD and established the trust relationship.

Now I have a 2003 domain (2 ADs) called NT, and a 2008 R2 domain (four 2008 R2 and three 2003) called DOMAIN.

I wanted to demote those 2003 ADs after transferring FSMO roles to 2008 R2 server. Everything went OK. Now 2008 R2 has all roles. Before I demote, I wanted to test to see anything complains if I just shutdown
three 2003 ADs.

Yes, the trust relationship broke and almost sametime NT BDC also crashed coinsidently. All 2008 ADs and 2003 ADs are up and running. PDC NT domain (this is actually 2003 domain) but BDC NT is down.

I once was able to establish one way trust relationship but it keeps dropping.

This thing is that I can access some servers from new domain to old without typing credentials.
I don't know what seems to be problem. Because of BDC down, it is not working?
I really appreciate if you can provide the steps and anwser my questions right away.

Thanks in advance
Question by:Ksean
    LVL 39

    Accepted Solution

    Please verify if you olso raised Forest Functional Level to 2003 and then test forest trust again.
    How to raise DFL and FFL you can find at

    LVL 7

    Assisted Solution

    by:Ilya Rubinshteyn
    BDC crashing would not prevent domain from working unless all your FISMOs as well as GC were on it. Verify your roles, ensure that GC is on both servers. You will have to reestablish the trust to the new DC's prior to removing the old ones to prevent any idiosyncrasies between 2k3 and 2k8

    Author Closing Comment


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    I know all systems administrator at some time or another has had to create a script to copy file from a server share to a desktop. Well now there is an easy way to do this in Group Policy. Using Group policy preferences is not hard. The first thing …
    Starting in Windows Server 2008, Microsoft introduced the Group Policy Central Store. This automatically replicating location allows IT administrators to have the latest and greatest Group Policy (GP) configuration settings available. Let’s expl…
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
    This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

    760 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    10 Experts available now in Live!

    Get 1:1 Help Now