[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

one way trust

Posted on 2014-12-24
6
Medium Priority
?
85 Views
Last Modified: 2015-01-17
Hi

I just setup a one way trust, what do I need to do to get users (Enterprise Admins) from the other domain to log into the domain controller in the other forest?
0
Comment
Question by:Jack_son_
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
6 Comments
 
LVL 17

Expert Comment

by:Tony Massa
ID: 40517295
Trusts grant no rights across trusting domains.  It only allows users to authenticate across domains.  You would have to add users to a group that grants the permissions that allow them to log on to domain controllers.  For example, add the users to "Account Operators", "Domain Admins", or "Enterprise Admins" (you should not do this, generally.)

If at all possible, never let "standard" user accounts log on to domain controllers or add them to sensitive groups.  Always require a secondary, administrative account for elevated access to domains/domain controllers.
0
 

Author Comment

by:Jack_son_
ID: 40521156
I can see the domain, although it will not allow me to see the users under the other domain.    Then when I rdp to the dc, it says the trust relationship failed.
0
 
LVL 27

Expert Comment

by:Steve
ID: 40521562
check you've got the trust the right way around.
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
LVL 17

Expert Comment

by:Tony Massa
ID: 40523051
Remember, trust direction is opposite of access direction.
If you want DOMAIN-A users to log on to DOMAIN-B, then you need to set up an INCOMING trust on DOMAIN-A or an OUTGOING trust on DOMAIN-B.

http://technet.microsoft.com/en-us/library/cc794933%28v=ws.10%29.aspx

As totallytonto mentions, you likely have the trust direction going the wrong way.
0
 

Author Comment

by:Jack_son_
ID: 40524817
Actually it connected for a bit, but now it says it cant reach the controllers.  This is pingable between the locations.  Perhaps there are additional DNS settings beyond what i setup?
0
 
LVL 27

Accepted Solution

by:
Steve earned 2000 total points
ID: 40531180
have you set the DNS forwarders for each domain's DNS servers so they can forward DNS requests for the other domain to the right DNS server?
0

Featured Post

Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question