Re: New AD Forest in an existing domain "Real World" gotchas?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance




Hi
To implement security boundaries the forest is the way to go. Regarding to systems administration of the new forest, you can create trusts (oneway twoway) that allow admins in one forest to administer the other depending of your real needs.
--
I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MCSE, MVP Directory Services

.



Relevant Pages

  • Re: 2003 AD upgrade and consolidation
    ... Right now they don't share resources across companies. ... GPOs are NOT inherited by child domains, ... That's resource sharing and trusts too. ... Create the new forest domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forest Trusts- roaming Laptops
    ... No trusts setup, no forest, just independent ... Senior HQ executives travel to sites with their laptops. ...
    (microsoft.public.windows.server.general)
  • Re: Interforest migration with domain name change
    ... I want to move now to server 2003 to server 08 by first: ... Upgrading my forest to 2003 by using a member server and promoting it. ... Forest trusts come first with 2003. ... Trusts across Windows Server 2003 and Windows 2000 forests: ...
    (microsoft.public.windows.server.migration)
  • Re: Trust relationships between sites.
    ... Trusts are between ... root forest domains of each forest.) ... Dump the LMHosts file and setup one or more WINS Server -- if you ... so that the DNS of Ad01 can resolve Ad02 and vice versa. ...
    (microsoft.public.win2000.active_directory)
  • Re: Huge AD deployment
    ... Trusts between forests only create a trust between the two specific domains ... either forest or from forest to forest. ... > company.com in that data center and have every country trust company.com ... instead of going over the internet. ...
    (microsoft.public.windows.server.active_directory)