Re: Trusts need to see all DC's on each side?

Tech-Archive recommends: Fix windows errors by optimizing your registry




"JPolicelli [MVP-DS]" <JPolicelliMVPDS@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:02A3205F-7A61-477D-A7C1-33BEEB0A3096@xxxxxxxxxxxxxxxx
One thing to keep in mind...when you create a trust, the users from the
trusted domain are added to the Authenticated Users group in the trusting
domain. As such, any permissions that are granted to the Authenticated
Users group in the trusting domain will incorporate the users from the
trusted domain. Also, by default members of the Authenticated Users group
have read access to virtually all objects in AD. While this is not usually
a concern, it is something to consider if you do not want information
disclosure type attacks.

Ah! Thank you. I didn't realize it added them automatically to that group
(although it makes sense).

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


.



Relevant Pages

  • Re: Users and local admin rights??
    ... You should add Authenticated Users group to what policy (for what ... If users can do their work with only users permissions then this is all they ... >> What would be your reasons to make users Power Users? ...
    (microsoft.public.security)
  • Re: Trusts need to see all DCs on each side?
    ... One thing to keep in mind...when you create a trust, the users from the trusted domain are added to the Authenticated Users group in the trusting domain. ...
    (microsoft.public.windows.server.active_directory)
  • Access to install fonts
    ... My user base is primarily members of the authenticated users group ... they are unable to install fonts on their ... local machines. ...
    (microsoft.public.windowsxp.security_admin)