Domain Trust Within Forest
However let s say that there is a trust between forest b and forest c as well.
Domain trust within forest. Active directory creates a foreign security principal object in the internal domain to represent each security principal from the trusted external domain. Indicate the domain 1 with which the trust relationship is made and click next 2. An external trust is a trust relationship in which a domain within your forest trusts a domain that does not belong to the forest. All groups participating in the forest trust the new domain owner and the service management practices of the new domain.
As microsoft explains it when a trust is established between a domain in a forest and a domain outside of that forest security principals from the external domain can access resources in the internal domain. This is where forest trust differs from external trust which is valid between two domains. Forest approval 1 and click next 2. All domain owners in the forest agree that the new domain owner has service administrator management and selection policies and practices that are equal to or more strict than their own.
In this case it would be helpful to create a shortcut trust to circumvent the forest domain hierarchy and give one object direct access to an object in a different tree. However in windows nt server there was no concept of a forest. The new domain owner trusts the forest owner and all the other domain owners. A forest trust can only be created between a forest root domain in one forest and a forest root domain in another forest.
When launching the wizard click next 1. We will also be talking about security identifiers sids. Typically these types of trusts are most often used for migrations. So if we establish forest trust between forest a and forest b that will also be valid between the child domains if any of these two forests.
In windows 2000 and 2003 a forest can contain multiple domains. Within a single forest all domains trust each other and you can escalate from one compromised domain to all the other as explained in sean metcalf s research on domain trusts. Go to the approvals tab 1 and click on new approval 2 to launch the wizard. Forest trusts are created between forest root domains and it is valid for all domains within the entire forest.
So domains within forest a and forest c will not have any trust relationships between them unless you manually configure a trust between forest a and forest c.