SCCM in Multiple forests and 2-way trust
Heh all.. Assumeing there is two-way trust enabled between the forests.... will the client machines from each of the forests, be able to read the AD Information from the other forests?
February 6th, 2012 6:37pm

If you are thinking of the information in the Systems Management container then no, client machines in a different forest will not be able to use this info. Read this article for details: http://technet.microsoft.com/en-us/library/bb694003.aspx
Free Windows Admin Tool Kit Click here and download it now
February 6th, 2012 6:46pm

nope, they will not. You need to ensure that the clients in the other forest has the installation commandline prepopulated e.g. using a GPO.Kent Agerlund | My blogs: blog.coretech.dk/kea and SCUG.dk/ | Twitter: @Agerlund | Linkedin: Kent Agerlund
February 6th, 2012 6:54pm

I find it easiest to place a primary site in each forest. John Marcum | http://myitforum.com/cs2/blogs/jmarcum/|
Free Windows Admin Tool Kit Click here and download it now
February 6th, 2012 7:37pm

Hi All... thanks a ton for all ur replies.... John.. Thankyou.. we do have a primary site there...... The main reason I asked this is because of the tangled situation in our environment. Kindly help me out. In the ForestB Location, there are around a 100 ForestA Domain workstations which share the same IP Subnet with ForestB workstations. Letme not explain again here. Kindly go through the thread below and give me ur inputs please.. Thankyou.... http://social.technet.microsoft.com/Forums/en-US/configmgrswdist/thread/ff378d5f-66c7-4209-978b-d44c562d3e00
February 7th, 2012 11:17am

If you have clients that fall within the boundaries of Forest B but the machine account lives in Forest A they should "roam" and use the MP/DP in forest B assuming that the primary site there is a child of the site in Forest A. John Marcum | http://myitforum.com/cs2/blogs/jmarcum/|
Free Windows Admin Tool Kit Click here and download it now
February 7th, 2012 4:34pm

It's worth being aware of the Kerberos requirements for authentication - http://blogs.technet.com/b/configurationmgr/archive/2010/02/11/configuration-manager-ad-system-discovery-will-not-work-across-external-trusts-starting-with-service-pack-2.aspxMy Microsoft Core Infrastructure & Systems Management blog - blog.danovich.com.au
February 8th, 2012 1:22am

John.. Im glad you understand the situation.... The ForestB server is indeed a child site of ForestA. But my question is.... will the machines which fall under ForestB boundary and whose accounts that live in ForestA.... when they roam into other Sites configured in ForestA... will they be able to locate a Local DP in ForestA (as they will be able to read the AD Site information) or will they only use regional roaming and use the DP in ForestB? Thankyou...
Free Windows Admin Tool Kit Click here and download it now
February 8th, 2012 4:06pm

I have never tested this but I am somewhat certain they will be able to find a DP. This is an unusal situation so you may not find a reliable answer. It's really easy to test this though if everything is already setup. John Marcum | http://myitforum.com/cs2/blogs/jmarcum/|
February 8th, 2012 11:15pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics