sub domain trust on Windows

Gong, Allen 95 Reputation points
2024-07-16T08:21:28.2933333+00:00

I am trying to setup a multiple domains environment on Windows, here is my setup:

User's image

My requirement is that users in parent domain (b1cloud.smes.sap.corp) can list users of its sub domains(child.b1cloud.smes.sap.corp, atlas.b1cloud.smes.sap.corp), but users in different sub domain can not list users of other domain, means users in child.b1cloud.smes.sap.corp can not list users in atlas.b1cloud.smes.sap.corp.

The actually behavior is that the different sub domain can list the user of other domain, it seems sub domains trust each others by default, is it possible to disable this trust? Is there any setting on Windows for this? Thanks.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,272 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,402 questions
0 comments No comments
{count} votes

Accepted answer
  1. Daisy Zhou 22,081 Reputation points Microsoft Vendor
    2024-07-16T08:49:03.2633333+00:00

    Hello Gong, Allen,

    Thank you for posting in Q&A forum.

    You can right click child.b1cloud.smes.sap.corp or atlas.b1cloud.smes.sap.corp and click the Properties, then check Trusts tab and check the trust relationship between child.b1cloud.smes.sap.corp and atlas.b1cloud.smes.sap.corp.

    If both child domains are listed under Trusts tab, it seems sub domains trust each others by default.

    In a Microsoft Active Directory (AD) environment, a parent domain and its child (sub) domains inherently trust each other in a hierarchical structure. This is known as a transitive trust.

    By default, these trusts are two-way and transitive, meaning that a parent domain trusts its child domains and vice versa. This transitive nature extends the trust to all domains within the parent-child hierarchy. If you want to manage or restrict the trust relationships between subdomains, maybe there are possible methods, but it's important to understand the implications as this can significantly impact your domain's functionality and security. Modifying or disabling the default trust relationships between parent and child domains is uncommon and not generally recommended because it can disrupt many AD functionalities.

    If you do not want users in one child domain to list users in the other child domain, you can try to block it via permissions on child Domain Controllers. For example: try to set block "Read" permission in the child domain.

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.