Creating a one way Transistive Truct wtih another Domain

Posted on 2014-08-27
Last Modified: 2014-09-04
We have 3 Domain in our environment we want collapse 2 of the domain under 1 Forest with a 1 way trust for centralized management.  How can this be achieved?
Question by:HyperTech1911
    LVL 14

    Expert Comment

    You'll definitely need to be using the Active Directory Migration Tool to restructure the domains - Can you please describe your current structure and desired structure, using DOMAIN1, DOMAIN2, DOMAIN3 and DOMAIN1\USER1, DOMAIN2\USER1 etc as examples? The question's just a little bit too expansive at the moment - Do you currently have 3 domains in 3 separate forests? And why specifically a 1-way trust?



    Author Comment

    Sorry for the delay in responding.   we have 2 domains.  One that the application group use.  and the Primary domain.  We do not want the application domain to be able to administer the Primary domain.   what is the best scenario?
    LVL 14

    Accepted Solution

    Ok. How big are the domains in question, roughly? And what domain level and Domain Controllers do you currently have?
    It's not actually possible to move the existing domain into another forest per se; what you'd be doing is setting up a new App domain in the Pri domain's forest, then using ADMT to migrate the User, Computer and Service accounts into the new domain, keeping security descriptors intact. The process is described
    here in a reasonable amount of detail. If all you want is to be able to grant users from Pri domain access to resources in the App domain, you don't actually need to move them into the same forest - you can just set up the trust and away you go. Given the number of steps involved in migrating the domain, you might want to consider setting it up that way for now and planning to merge the domains over a longer period as you commission and retire hardware/users.

    Author Comment

    Great! I Agree!  thank you for the good advice! Regards.

    Featured Post

    New My Cloud Pro Series - organize everything!

    With space to keep virtually everything, the My Cloud Pro Series offers your team the network storage to edit, save and share production files from anywhere with an internet connection. Compatible with both Mac and PC, you're able to protect your content regardless of OS.

    Join & Write a Comment

    A common practice in small networks is making file sharing easy which works extremely well when intra-network security is not an issue. In essence, everyone, that is "Everyone", is given access to all of the shared files - often the entire C: drive …
    Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
    Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
    In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…

    728 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now