Anda di halaman 1dari 2

Below are the basic steps needed to configure a Two-Way trust between two

Windows 2003 domains in different forests.


1) Configure DNS to resolve each of the two domains DNS names
a. Example: my.domain.local and your.domain.local
2) Verify cross DNS works
a. On a DC from each domain ping the other domain by name
b. If this does not work, investigate, correct and repeat.
3) Perform the following on the both domains at the same time*
a. *within minutes of each other
4) Open AD Domain and Trusts
5) Click domain properties
6) Click the New Trust Button
a. The New Trust Wizard appears
b. Click Next
c. Trust Name page
i. Type: the other domain’s domain name (my.domain.local)
ii. Click next
d. Direction of Trust
i. Select “Two-way”
ii. Click next
e. Sides of Trust page
i. Click “This domain only”
ii. Click Next
f. Outgoing trust authentication level
i. Select “Domain-Wide authentication”
ii. Click next
g. Trust password page
i. Enter: type password (keep it simple)
ii. Click next
h. Summary page
i. Click next
i. Confirm outgoing Trust
i. Select Yes
ii. Click Next
j. Confirm incoming trust
i. Select No
ii. Click Next
k. Click Finish
7) Test adding users
a. Create a Test “Domain Local” group in each domain
b. Add “Administrator” or “Guest” from the other domain to the group
c. If this works without prompting for credentials, then the trust is
successfully established.
d. If you are prompted for credentials, then wait up to 24 hours for trust
information to be replicated. After 24 hours, rebuild trust verifying initial
trust passwords are the same.
e. Remember, in a multiple domain forests, the trust is only between to
specific domains. Therefore, the users performing these tests must be
members of the respective domain involved in the trust.

Anda mungkin juga menyukai