TheaterFire

Setting up a new Domain Trust, looking for advice especially in regards to security, for our scenario

Posted by HyperPixel5@reddit | sysadmin | View on Reddit | 2 comments

Reply to Post

2 Comments

bhazlewood@reddit

The Microsoft terminology is confusing, certainly. Technically, the trust needs to be established in both domains, but you are correct, you want to have a one-way outgoing trust in "Main" and then use "Branch" groups to provide access to the limited resources needed by "Branch" users. (After the trust is created, you would see a one-way incoming trust in the Branch domain, from Main.)
View on Reddit #1905043

HyperPixel5@reddit (OP)

Quite confusing, yes. I have this currently set up in our testlab, and interestingly, when I open up a domain-local group in "Main", I can only add groups from "Branch" in the Member-Of tab. I expected that I would be able to add foreign groups under "Members", but the Branch-Domain does not even show up as an option to expand somehow.
View on Reddit #1905541