Solved

Transitive Trust with an External Domain to a Child Domain..?

Posted on 2013-11-27
1
1,385 Views
Last Modified: 2013-11-27
The company I'm working with is a holding company that wants to bring newly acquired businesses under it's Internal company Forest Domain.

The odd part here for me is that they have created a Internal Child Domain under the Internal Forest Root called "Trust" and they want to create a transitive trust with the External Domain to the Trust Domain instead of Forest Root to Forest Root of each company.

I'm not sure what kind of trust to create here. A Forest Trust is forest root to forest root and in this scenario it would be external forest root to internal child domain. Should that be an External trust then..? They are both Windows Domains 2008R2.

After the trust is setup, they will begin sharing resources between the External Forest Root and the Internal Forest Root but they don't want the External Company to be able to access resources in the other Internal Child domains. I see the Trust Child Domain as superfluous really and complicates the trust model.

So if they are tied to this model, should the trust between the External Domain be an External Trust to the Internal Trust Child Domain keeping in mind that eventually all the objects from the External Domain will eventually be brought under the Internal Forest Root Domain..?
Here's the model they want in action...Thanks,
0
Comment
Question by:MarkSatori
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 17

Accepted Solution

by:
Tony Massa earned 500 total points
ID: 39682711
An external trust is the trust created between two domains (can be one-way or two-way).  No possible way for transitive access to other domains, even within the same forest.

Your scenario would require all individual external trusts or a forest trust.

There is no such thing as an external trust proffering transitive access to another domain.
http://technet.microsoft.com/en-us/library/cc773178%28v=ws.10%29.aspx

In your scenario, you would have to create a one or two-way trust between xyz.com and trust.abc.net.  In addition, you would likely create a two-way trust between the forest root abc.net and xyz.com.

The trusts you create will depend on the location of the user and resources.  In any case, go with external...this way you won't grant any transitive access by using the forest trust to other child domains in the abc.net forest.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Azure AD / OAUTH 2 43
GPO denied - but why ? 6 54
Office 365:  Hybrid without everyone DirSync 5 64
NTDS CN=Infrastructure FSMORoleOwner 5 13
A hard and fast method for reducing Active Directory Administrators members.
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question