Two-way Trust Question
I'm in the process of creating a two-way non-transitive forest trust between a Windows Server 2003 domain and a Windows Server 2008 domain. When the trust is actually created, are both domains listed in the "Log On To" login dialog box on each workstation/member server?
January 11th, 2009 9:02pm

Yes, this will happen automatically for pre-vista (including Windows Server 2003).However, Vista and WIndows 2008 are a little different...as they don't have a "Log On To"...you need to use the UPN (user@domain.local) or Standard (Domain\User) to log into the domain.More info: http://blogs.technet.com/ad/archive/2008/01/04/the-domain-logon-dialogue.aspx The Windows interactive logon pull down menu for domains is created by contacting a Global Catalog and querying for domains. Global Catalogs are forest specific and hence will only know of domains in their own forest. Therefore, the list will not contain domains in a trusted forest other than the root domain. In other words, the MSGINA domain drop-down list retains the same functionality but with the use of forest trust rather than external trusts the list will contain only the root domain of each forest trusted by the forest in which the machine account resides. Additionally, there is no built-in method in the interactive logon menu which knows to query Global Catalogs of trusted forest(s). Windows Vista and Server 2008 interactive logon menu behavior does not provide a pull down menu at all and hence this is not a concern in those releases (this stems from the new CredUI replacing GINA functionality). For Vista and 2008 UPN or UNC are the typical format for the user account name for domain logon. This behavior is discussed at length in the Technet article below. That article goes into great depth on other places where the user interface behaves differently across forests as well in the Logons and Authentication section, things which I am not discussing here. http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/fedffin2.mspx John GilhamPrincipal Consultant Gilham ConsultingAdvanced Microsoft Solutions Web: www.Gilham.org
Free Windows Admin Tool Kit Click here and download it now
January 12th, 2009 5:33am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics