ADDS Forest Trust question

KINGJULIAN 1 Reputation point
2020-10-01T11:22:51.697+00:00

I have a query about ADDS domain trusts as i cannot wrap my head around it, allow me to build a quick scenario

2 forests forestA and forestB - They are able to resolve each other via DNS and are single domain environments S2016

Trust - 1-way transitive

ForestA -Incoming trust

ForestB - outgoing trust

Question.... This means ForestA is trusted and ForestB is trusting.. Correct?

what i do not understand is this

If i have 2 DC's we will say DCa and DCb - DCa is a domain controller within Foresta and DCb is a domain controller within Forestb

When Foresta\administrator is logged into DCa i can open ADUC and browse Forestb's domain however cannot write to it

When Forestb\administrator is logged into DCb i can write to Foresta's ADDS such as creating a new user

How is this correct unless i have the whole trusted/trusting mixed up?

However the permissions are the opposite and what you would expect, Foresta cannot assign permissions like NTFS to groups from Forestb however it works in reverse so Forrestb can assign permissions to groups in Forresta

It seems the administration side is working against the grain of the trust relationship

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,484 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,443 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Fan Fan 15,326 Reputation points Microsoft Vendor
    2020-10-02T00:14:21.427+00:00

    Hi,
    Here is my test to single domain forest:pki.com and fan.local
    Trust - 1-way transitive

    fan.local -Incoming trust
    pki.com - outgoing trust

    When fan.local \administrator is logged into DC1.fan.local , i can open ADUC and browse pki.com domain however cannot write to it,the access was denied. It is an expected behavior.
    When pki.com\administrator is logged into DC1.pki.com, i can't even browse pki.com domain ,the error is:
    29735-1021.jpg

    In your situation , i would recommend you confirm the trust again and the if the permission is delegated .


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.