you might want to describe to us what your actual goal is for creating a non-fully trusted domain in your AD forst.  Maybe you can reach a similar goal by using the fairly powerful capabilities in AD to delegate administration of objects within a domain. You can also use these features to hide specific parts of AD from the rest of the organization and thus create a "semi-isolated" units within a single AD domain. 
 
Note that there is no way to fully isolate any objects within a domain or forest from domain or enterprise admins - if you do need full administrative isolation, you have to create multiple forests.
 
/Guido


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Almeida Pinto, Jorge de
Sent: Saturday, July 22, 2006 12:45 AM
To: [email protected]
Subject: RE: [ActiveDir] Domain Trusts.

1-yep
2-yep
 
Met vriendelijke groeten / Kind regards,
Ing. Jorge de Almeida Pinto
Senior Infrastructure Consultant
MVP Windows Server - Directory Services
 
LogicaCMG Nederland B.V. (BU RTINC Eindhoven)
(   Tel     : +31-(0)40-29.57.777
(   Mobile : +31-(0)6-26.26.62.80
*   E-mail : <see sender address>


From: [EMAIL PROTECTED] on behalf of Matt Hargraves
Sent: Sat 2006-07-22 00:35
To: [email protected]
Subject: Re: [ActiveDir] Domain Trusts.

So basically there's no way to have a domain in a forest that doesn't fully trust every other domain in the forest?

The only way to have a non 2-way trust is to make a separate forest?

Reply via email to