Solved

Transitive trusts and existing child domains

Posted on 2013-02-07
1
747 Views
Last Modified: 2013-02-25
If i look at MS Technet article around AD Forest trusts it states:

"Each time you create a new domain in a forest, a two-way, transitive trust relationship is automatically created between the new domain and its parent domain. If child domains are added to the new domain, the trust path flows upward through the domain hierarchy extending the initial trust path created between the new domain and its parent domain."

Does this mean that this automatic relationship is not created for existing child domains that were there before the trust was created? Do these need to be done manually?

Reason for question is that I am seeing this where Root Forest domain for Forest A doesn't trust child domains of Forest B and vice versa.
0
Comment
Question by:jafar54
1 Comment
 
LVL 17

Accepted Solution

by:
Tony Massa earned 500 total points
ID: 38863549
It seems you're mixing intra-forest trust (parent-child) with external forest trust.
To your point, if you create a TWO-WAY forest trust, then there should be a transitive trust between all domains in each forest: http://technet.microsoft.com/en-us/library/cc773010(v=ws.10).aspx
Creating a forest trust between two Windows Server 2003 forests provides a one-way or two-way, transitive trust relationship between every domain residing within each forest
Are you sure that the trust was established as a two-way?  Can users from every other domain access resources in each of the other domains?

I would contend that it could be a problem with DNS resolution, maybe theres a duplicate NETBIOS name, or some other problem...new child domains should be automatically trusted in a two-way external forest trust.  From a domain computer in Forest A, can you browse to the NETLOGON folder on the new domain in forest B?

\\new.domain.FQDN\netlogon
0

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now