Trust and Foreign Security Principals in WS 2012r2

InfoTechdude 156 Reputation points
2021-01-08T15:26:37.827+00:00

Hi.

I was wondering about the connection of AD Trust and Foreign Security Principals. What is the reason such option exist. Can this be changed/manipulated or another words can this FSP be operated on somehow (via like adsiedit)?

54790-fsp.jpg

Thank you for your insight into the matter,

Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,601 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,657 questions
{count} votes

Accepted answer
  1. Fan Fan 15,341 Reputation points Microsoft Vendor
    2021-01-11T05:49:42.577+00:00

    Hi,
    A Foreign Security Principal (FSP) is an object created by the system to represent a security principal in a trusted external forest. These objects are created in the Foreign Security Principals container of the domain. They can be added to domain local security groups and granted permissions.
    For example: When adding a user from domain A for the first time to a group from domain B from another forest, this creates an FSP in domain B and adds this FSP to the group from domain B.
    For your reference:
    https://social.technet.microsoft.com/wiki/contents/articles/51367.active-directory-foreign-security-principals-and-special-identities.aspx

    If there orphaned Foreign Security Principals in the container, you can clean up them through ADUC,ADSI or PowerShell command.
    For your reference:
    https://4sysops.com/archives/clean-up-orphaned-foreign-security-principals/(Third-party link)
    This response contains a third-party link. We provide this link for easy reference. Microsoft cannot guarantee the validity of any information and content in this link.

    Best Regards,


1 additional answer

Sort by: Most helpful
  1. balasubramaniam 21 Reputation points
    2023-10-02T10:18:21.1066667+00:00

    thank you for the above answer.

    why do we have to remove stale foreign security principles

    does it give any benefits for an active directory forest? else just a clean-up process


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.