you might want to describe to us what your actual goal is
for creating a non-fully trusted domain in your AD forst. Maybe you can
reach a similar goal by using the fairly powerful capabilities in AD to delegate
administration of objects within a domain. You can also use these features to
hide specific parts of AD from the rest of the organization and thus create a
"semi-isolated" units within a single AD domain.
Note that there is no way to fully isolate any objects
within a domain or forest from domain or enterprise admins - if you do need full
administrative isolation, you have to create multiple
forests.
/Guido
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Almeida Pinto, Jorge de
Sent: Saturday, July 22, 2006 12:45 AM
To: [email protected]
Subject: RE: [ActiveDir] Domain Trusts.
1-yep
2-yep
Met vriendelijke groeten / Kind regards,
Ing. Jorge de Almeida Pinto
Senior Infrastructure Consultant
MVP Windows Server - Directory Services
LogicaCMG
Nederland B.V. (BU RTINC Eindhoven)
( Tel
: +31-(0)40-29.57.777
( Mobile : +31-(0)6-26.26.62.80
* E-mail : <see sender
address>
From: [EMAIL PROTECTED] on behalf of Matt Hargraves
Sent: Sat 2006-07-22 00:35
To: [email protected]
Subject: Re: [ActiveDir] Domain Trusts.
So basically there's no way to have a domain in a forest that doesn't fully
trust every other domain in the forest?
The only way to have a non 2-way trust is to make a separate forest?
The only way to have a non 2-way trust is to make a separate forest?
