Creating a one way Transistive Truct wtih another Domain

We have 3 Domain in our environment we want collapse 2 of the domain under 1 Forest with a 1 way trust for centralized management.  How can this be achieved?
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

You'll definitely need to be using the Active Directory Migration Tool to restructure the domains - Can you please describe your current structure and desired structure, using DOMAIN1, DOMAIN2, DOMAIN3 and DOMAIN1\USER1, DOMAIN2\USER1 etc as examples? The question's just a little bit too expansive at the moment - Do you currently have 3 domains in 3 separate forests? And why specifically a 1-way trust?


HyperTech1911Author Commented:
Sorry for the delay in responding.   we have 2 domains.  One that the application group use.  and the Primary domain.  We do not want the application domain to be able to administer the Primary domain.   what is the best scenario?
Ok. How big are the domains in question, roughly? And what domain level and Domain Controllers do you currently have?
It's not actually possible to move the existing domain into another forest per se; what you'd be doing is setting up a new App domain in the Pri domain's forest, then using ADMT to migrate the User, Computer and Service accounts into the new domain, keeping security descriptors intact. The process is described
here in a reasonable amount of detail. If all you want is to be able to grant users from Pri domain access to resources in the App domain, you don't actually need to move them into the same forest - you can just set up the trust and away you go. Given the number of steps involved in migrating the domain, you might want to consider setting it up that way for now and planning to merge the domains over a longer period as you commission and retire hardware/users.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
HyperTech1911Author Commented:
Great! I Agree!  thank you for the good advice! Regards.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Network Management

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.