RE: pass-through authentication

From: S.J.Haribabu (sjhari_at_microsoft.com)
Date: 08/19/04


Date: Thu, 19 Aug 2004 23:11:09 GMT

Hi,

Windows 2000 has implicit trust relationships with a
domain tree, and between trees in a forest, are transitive and
bi-directional by default, the single sign-on provides access not
only to the entire domain, but to all domains in the Windows 2000
forest. When a user has been authenticated to one domain in a
forest, referral or pass-through authentication provides access
to resources on computers that reside in other domains within the
forest.

But windows NT domains on your network, trust
relationships are not implicit; they must be created by the
administrator. Additionally, they are one-way and non-transitive
so you must create two explicit trusts between each pair of NT
domains – or NT domain and Windows 2000 domain – in order to
enjoy pass-through authentication throughout the network.

Thanks,
sjhari@online.microsoft.com

This posting is provided "AS IS" with no warranties, and confers no rights.

 



Relevant Pages

  • Re: Raising the Domain and Forest Mode
    ... See also this article because of different security settings between NT4 and 2003 trust. ... domain (Windows Server 2003 Domain Mode) and a Windows NT domain, ... What you can think about is using forest trust's instead of two-way. ... The functional levels of the domain/forest are ...
    (microsoft.public.windows.server.active_directory)
  • Re: Re: Re: Re: Gradually migrate from Win2000 to Win2003 AD
    ... > Thanks for the info. Windows 2003 is quite new to me so I will have to ... > NTFS is far more effective and adding share permissions only ... >> This is approximated by Forest level trusts. ... >> trust between the two forests to be transitive to all ...
    (microsoft.public.win2000.active_directory)
  • Re: AzMan with 2000 mixed DC
    ... One of the reasons W2k3 domain and forest funtional levels ... the roles has map to back over the trust. ... Microsoft MVP (Windows Security) ... > We are deploying an application which uses AzMan, with the store in AD, ...
    (microsoft.public.security)
  • Re: Domain Functional Levels and Trusts
    ... > a Windows 2000 Mixed Mode domain? ... >>> I need to build a trust between two domains in separate forests. ... >>> Domain Functional Level. ... >> a pair of domains which are not in the same forest. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD trust RPC
    ... I have a two way transistive trust between two 2003 native mode ... DC1 is a DC in my forest, T1server2 is a DC in the other ... The session setup to the Windows NT or Windows 2000 Domain Controller ...
    (microsoft.public.windows.server.active_directory)