Domain Trust
I've been ask to set up a new domain using Windows 2008 R2. The company is currently on Windows 2003 domain but the company is changing its name and therefore it's domain name. I am setting up the w2k8 domain with the new domain
name but I am going to need to create a two way trust to the current w2k3 domain. During setup, I am giving the choice to select the forect functional level. Since there will be only w2k8 r2 DCs in the new domain, should I choose Windows 2008 R2?
If I choose this level, will i still be able to create the two trusts between the current, w2k3 domain, and the new w2k8 r2?
August 24th, 2011 10:25am
are you going to create a new domain in existing forest or your going to create a new forest for the new domain ?http://www.virmansec.com/blogs/skhairuddin
Free Windows Admin Tool Kit Click here and download it now
August 24th, 2011 11:48am
Hello,
for forest trust, 2003 FFL is required.
Since there will be only w2k8 r2 DCs in the new domain, should I choose Windows 2008 R2?
If you are not planning to add DCs in your domain with OS lower than 2008 R2 then raise your DFL to 2008 R2
If you are not planning to add DCs in your forest with OS lower than 2008 R2 then raise your FFL to 2008 R2. Like that you can use AD recycle Bin.
If I choose this level, will i still be able to create the two trusts between the current, w2k3 domain, and
the new w2k8 r2?
Yes, of course.
This
posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Microsoft Student
Partner 2010 / 2011
Microsoft Certified Professional
Microsoft Certified Systems Administrator:
Security
Microsoft Certified Systems Engineer:
Security
Microsoft Certified Technology Specialist:
Windows Server 2008 Active Directory, Configuration
Microsoft Certified Technology Specialist:
Windows Server 2008 Network Infrastructure, Configuration
Microsoft Certified Technology Specialist:
Windows Server 2008 Applications Infrastructure, Configuration
Microsoft Certified Technology Specialist:
Windows 7, Configuring
Microsoft Certified IT Professional: Enterprise
Administrator
Microsoft Certified IT Professional: Server Administrator
August 24th, 2011 11:58am
Hi,
To understand functional levels, you may refer to the following Microsoft TechNet article:
Understanding Active Directory Domain Services (AD DS) Functional Levels
http://technet.microsoft.com/en-us/library/understanding-active-directory-functional-levels(WS.10).aspx
After that, you should know if you need Windows Server 2008 R2 forest functional level.
In addition, you still can create forest between functional level Windows Server 2003 and Windows Server 2008 R2.
Regards,Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
August 24th, 2011 11:18pm
If you functional lebel is not same you can create external trust.
http://technet.microsoft.com/en-us/library/cc755427(WS.10).aspxBest regards Biswajit Biswas Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights. MCP 2003,MCSA 2003, MCSA:M 2003, CCNA, MCTS, Enterprise Admin
August 25th, 2011 3:10am
You need to have same level in both domain.
In youre example set both to 2003 forest functionality level
Free Windows Admin Tool Kit Click here and download it now
August 25th, 2011 3:28am


