Re: One-way inbound trusts



I will just add to Brian's great advise, as I notice that all discussion
was about domains, with no mention of forest.

If the new domain is within the forest of the other domain, then you
would really not be gaining as much as you may think since the
inherent trusts between domains within a forest will exist. You could
still exert control over much for limited user accounts of the other
domain, along the lines Brian outlined.

Either way (one or two forests) however, setting up a new domain is
not something one does on a whim in order to attempt solving some
believed need.
Rather, as suggested, it should be well thought through and planned.

"Wowbagger" <none> wrote in message
news:eCk33P8OGHA.1288@xxxxxxxxxxxxxxxxxxxxxxx
In our office environment there is an existing domain that everybody uses,
hosted on a server over which I have no control. I want to create a
separate domain on a new server for our own private workgroup complete
with a separate domain, entirely separate from the other.

Will a one-way inbound trust allow any authorized in existingdomain access
newdomain?




.



Relevant Pages

  • Re: Can a cluster node act as the domain controller for the cluster?
    ... Well I run a corporate Active Directory and I think it would be very unusual ... to run a product on a separate domain in my forest. ... require two domain controllers for redundancy. ... >> Needing a separate domain for the cluster is an odd requirement. ...
    (microsoft.public.windows.server.clustering)
  • Re: ISA Server 2004 Should Authenticate to Separate Forest?
    ... what about the idea of having a separate domain within ... > one forest just for authenticating machines on the external DMZ networks, ... You are correct about Windows 2000 cross-forest trusts using NTLM, ...
    (microsoft.public.isa)
  • Re: Domains vs. OUs
    ... The reasons for going with a separate domain would be political issues ... Enterprise admins can affect all the domains in the forest. ... forest and insists we become an OUunder a single domain. ... relinquishing control of our domain to corporate because of their history. ...
    (microsoft.public.win2000.active_directory)
  • Re: Child domain on same server as parent
    ... here is the rest of the conversation Innes ... A separate domain seemed a more ... time you can add a new domain to the forest (or start a new forest depending ... > A domain controller can only be a domain controller for one domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Ad in DMZ
    ... Separate domain in the same forest is not a good option ... make a server VLAN, LAN VLAN and DMZ VLAN, and use IPSec. ... > containing user accounts to login to the e-commerce sites. ...
    (microsoft.public.windows.server.active_directory)