Forest trusts and GPOs

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hello All,
I am in the middle of creating a two way forest trusts in my environment. I
am wondering how does this effect my GPOs?

Suppose ClientA logs on usually to DomainA and all GPOs work as expected.
Now, ClientA needs to logon to DomainB for authentication, I assume that the
GPO for clientA will still be applicable but only for the Computer
Configuration portion. Whereas the User Configuration portion will only be
applied if configured on DomainB. How does one go about about managing GPOs
from DomainA and ensuring that they are applied even if users logon onto
DomainB?

After looking around I have found some articles stating that GPOs cannot be
linked across forests and that in order to have GPOs applied the GPOs have
to be applied from the authenticated domain. Can someone point me to any
good articles that discuss this topic more in depth (that is GPOs and forest
trusts). Since designation of GPO via OU is not applicable for me due to
environmental circumstances, I am wondering if this can occur via Sites
since the the users of the two domains are access distinct areas
(geographically).

TIA,
Altria



.



Relevant Pages

  • Re: Forest trusts and GPOs
    ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Suppose ClientA logs on usually to DomainA and all GPOs work as expected. ... Whereas the User Configuration portion will only be ... applied if configured on DomainB. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Insufficient rights to edit all GPOs in local forest from account in trusted forest.
    ... such as GPOs, in order to impact the security set on newly defined ... trusting forest that are Domain Admins there. ... I have a group in Forest A called "Forest A Admins" ... This group is a member of the BUILTIN\Administrators group in Forest B. ...
    (microsoft.public.windows.server.security)
  • Re: SITE LEVEL AND DOMAIN LEVEL PLICIES
    ... GPOs that are linked to Active Directory site objects affect all ... any Group Policy object that is ... linked to a site is applied to all computers in that site, ... regard to which domain (in the forest) contains the computers. ...
    (microsoft.public.win2000.group_policy)
  • Re: ADMT - Copying GPOs - Forest trust
    ... Do you have Software Installation policy in the source forest GPOs that you are trying to migrate? ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADMT - Copying GPOs - Forest trust
    ... No there is no software restriction policies in the source or the target. ... have copied the GPOs over ignoring the message and started the pilot ... Installation policy in the source forest GPOs that you are trying to ... It could be something as simple as a native object that it's ...
    (microsoft.public.windows.server.active_directory)