Re: SMS 2003 Hierarchy within W2k3 Federated Forests

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Ian Bing (IanBing_at_discussions.microsoft.com)
Date: 09/02/04


Date: Thu, 2 Sep 2004 01:19:03 -0700

Thanks Luke

"Luke Packard [MSFT]" wrote:

> 2 way communication is required for site to site communication. A 2 way
> trust is not required for site to site communication. In you case you will
> need to create all site address accounts in the parent forest. Grant the
> account used for parent to child communication membership in the child
> site's sitetositeconnection group and grant the account used for child to
> parent communication membership in the parent's site's sitetositeconnection
> group. You can do this whether the sites are in standard or advanced
> security.
>
> --
> Luke Packard [MSFT]
>
> SMS 2003 Technical FAQ:
> http://www.microsoft.com/technet/prodtechnol/sms/sms2003/techfaq/default.mspx
>
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
> "Ian Bing" <IanBing@discussions.microsoft.com> wrote in message
> news:3E8E3DEC-BDA8-4486-889A-79E87EB9392D@microsoft.com...
> > I'm trying to design a SMS 2003 hierarchy within a complicated
> > multi-forest
> > environment. Each forest will have a single domain only. The top "parent"
> > forest can only have a one-way, non-transitive trust (external) to each of
> > the "child" forests, i.e. the child forests can trust the parent but not
> > vice
> > versa.
> >
> > I would like to implement an SMS infrastructure that would be controlled
> > within the "parent" forest only.
> >
> > I know in multi-forest enviroments there needs to be primary sms site in
> > each forest. However for SMS site-site communications MS documentation
> > says
> > the following is required:
> >
> > · You are using the Windows Server 2003 family.
> > · The forest functional level is set to Windows Server 2003.
> > · SMS is running in advanced security mode.
> > · The forests are configured with a transitive trust.
> >
> > Surely if there is only one domain in each trust, using a non-transitive
> > trust does not matter?
> > Also, does the trust need to be 2-way? For sms site to site communication
> > to
> > occur, information needs to flow both ways!
> >
> > Thanks
> > --
> > Ian Bing
> > Microsoft Consultant
> > SCC Ltd
>
>
>



Relevant Pages

  • Re: convert multicolumn/multirow table into two structured/formatt
    ... the following table (only account numbers, ... where the parent account is always on the right (B1 parent of ... RowCount = RowCount + 1 ... (until the highest level) ...
    (microsoft.public.excel.programming)
  • Re: convert multicolumn/multirow table into two structured/formatt
    ... the following table (only account numbers, ... where the parent account is always on the right (B1 parent of ... RowCount = RowCount + 1 ... (until the highest level) ...
    (microsoft.public.excel.programming)
  • Re: RegNotifyChangeKeyValue and ipc?
    ... parent process does a search for a certain wordwith certain criteria ... it is effectively slower if you have multiple processes because the process swap ... of the children are blocked "listening" for a registry key to change. ... Don't even bother thinking any further about this as a way of communication. ...
    (microsoft.public.vc.mfc)
  • Re: Trust Validation
    ... credentials and it says that cross policy is being applied to their account. ... trust again to see what happens. ... I assume you have dns secondary's of each others forests. ... I actually am getting the trust to validate now. ...
    (microsoft.public.windows.server.active_directory)
  • Re: convert multicolumn/multirow table into two structured/formatted columns
    ... The data (account names) are already in area A1:N3100. ... top/final parent account "Total Assets", and for others, they will need only ... RowCount = RowCount + 1 ... (until the highest level) ...
    (microsoft.public.excel.programming)