Authentication in a multi-domain forest



Hey, everyone:

I'm looking for a bit of information about how clients in one domain can authenticate to resources in another domain (provided that both are in the same forest, with all default transitive trusts in place and no shortcut trusts.)

Suppose a forest has three domains: a parent named company.com, and two child domains named sales.company.com, and research.company.com. What we have noticed in our environment, similar to the one above, is that if a sales user logs on to a computer in the research domain, and attempts to access a resource in the company domain, there are requests for Kerberos and LDAP that go to the root, company.com DCs.

Does anyone know why this would be? I thought that the user would authenticate to their DC, and that credentials would be passed from DC to DC. If there is a white paper on intra-forest authentication, I would love to read it, I searched the KB articles, but couldn't find one.

Thanks for any information!

-Steve Athanas
.



Relevant Pages

  • RE: CIFS and Windows Server 2003
    ... current version you are using is compatible with Windows 2003 server. ... Microsoft Online Partner Support ... |using this server to authenticate users trying to access NetBIOS ... |resources on the HPUX box. ...
    (microsoft.public.windows.server.active_directory)
  • Re: I need a method a way to ONLY allow computers in domain to login
    ... > you could not access network resources. ... You must authenticate TO logon. ... police use AH (authentication of packet data) -- no non-Domain ...
    (microsoft.public.win2000.security)
  • Re: Outgoing mail
    ... > you didn't authenticate to their server (to prove you have permission to ... > use their resources) and since you are coming from a different domain, ... > If you are ON the same network as the mail server that you want to use, ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: How to change domain name?
    ... parallel migration and migrate all the users and resources from the NT ... > of joesfruitemporium.com with the old NT domain as 'apples'. ... > login they use the old NTdomain of apples\username to authenticate. ...
    (microsoft.public.win2000.active_directory)

Loading