Solved

Transitive trusts and existing child domains

Posted on 2013-02-07
1
751 Views
Last Modified: 2013-02-25
If i look at MS Technet article around AD Forest trusts it states:

"Each time you create a new domain in a forest, a two-way, transitive trust relationship is automatically created between the new domain and its parent domain. If child domains are added to the new domain, the trust path flows upward through the domain hierarchy extending the initial trust path created between the new domain and its parent domain."

Does this mean that this automatic relationship is not created for existing child domains that were there before the trust was created? Do these need to be done manually?

Reason for question is that I am seeing this where Root Forest domain for Forest A doesn't trust child domains of Forest B and vice versa.
0
Comment
Question by:jafar54
1 Comment
 
LVL 17

Accepted Solution

by:
Tony Massa earned 500 total points
ID: 38863549
It seems you're mixing intra-forest trust (parent-child) with external forest trust.
To your point, if you create a TWO-WAY forest trust, then there should be a transitive trust between all domains in each forest: http://technet.microsoft.com/en-us/library/cc773010(v=ws.10).aspx
Creating a forest trust between two Windows Server 2003 forests provides a one-way or two-way, transitive trust relationship between every domain residing within each forest
Are you sure that the trust was established as a two-way?  Can users from every other domain access resources in each of the other domains?

I would contend that it could be a problem with DNS resolution, maybe theres a duplicate NETBIOS name, or some other problem...new child domains should be automatically trusted in a two-way external forest trust.  From a domain computer in Forest A, can you browse to the NETLOGON folder on the new domain in forest B?

\\new.domain.FQDN\netlogon
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Office 2016 GPOs in Server 2012R2 5 28
Wild Card CName in Windows Active Directory integrated zone - Good Idea? 4 26
Event 4625 - Account Name: _ 3 28
Problem to setup GUI 11 33
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question