Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Forest to Forest Trust and OU Management

Status
Not open for further replies.
Apr 5, 2005
1,484
US
Requirement: Set up a one way external trust between two forests and allow a single OU to be managed by from the external forest.
What I have done so far:
Created a trust between domain A and B. In domain A I have created a delegation that allows a global group from domain B the rights to mange users within an OU in domain A. No issues with setting this up.
My issue:
From Domain B using ADUC, I am assuming I can connect to domain A so that I can see the OU in which I have right to manage. I recieve the following error when connecting from domain B to domain A in ADUC. "Windows cannot connect to the new domain because: Logon Failure: The machine you are logging onto is protected by an authentication firewall. This specified account is not allowed to authenticate to the machine."

I am researching the issue and hope to hear from some of you who have set up forest to forest trusts.

Thanks...
 
For those who are interested I found the issue. I was using selective authentication not domain-wide authentication. With selective authentication you have to manually add access to all objects you want the user, from the trusted domain, to have access to. To do this you have to set an ACL "Allowed To Authenticate" on the object. Cool stuff...

Now I can go home...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top