Domain Trust Network Requirements
The domain controllers and active directory section in service overview and network port requirements for windows.
Domain trust network requirements. We have multi domain active directory forest with a few external trusts. In a one way trust between domain a and domain b users in domain a can access resources in domain b. Some one way trusts can be either non transitive or transitive depending on the type of trust being created. Document the type of trust transitivity direction business need for the trust anticipated duration of the trust credentials domain forest principal information name dns ip addresses.
In many organizations trusts were implemented years sometimes 10 ago without major considerations given to security. However users in domain b can t access resources in domain a. The domain network is automatically detected when your computer is a member of active directory domain network. This type of network will enable most networking features of windows 10 like file sharing network device setup network discovery etc.
220 chapter 4 securing the network management process figure 4 11 trust transitivity in domains. A bidirectional trust path between windows domains is required when the client and the service are in different domains. In plain english this means that using transitivity of trust a user in any domain can access any resource in any other domain in the same forest. Bob is using his workstation in the alpha domain.
In a two way trust domain a trusts domain b and domain b trusts domain a. Otherwise kerberos extensions from microsoft called service for user s4u do not work. That workstation will check with it s own dcs to get the relevant trust information. 220 chapter 4 securing the network management process figure 4 11 trust transitivity in domains.
Bob from alpha domain is trying to log in to a workstation that s in omega domain. Use this network type if you trust the network you are connecting to. For the operation of the trust this port is not required it is used for trust creation only. Then the workstation will contact a dc from alpha verify the user and login.