Windows Active Directory two way trust

Shola Lawani 531 Reputation points Microsoft Employee

Hello Experts,

So if I have two different Windows Active Directory forest (Forest A and Forest B) and then configure a trust between them. If I extend Forest A to Azure (deploying additional domain controllers in Azure for Forest A and then setting up AD replication), can an Azure VM join and resolve to Forest B, if the Virtual Network DNS IP has been configured as the Forest A VM?

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,029 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,548 questions
0 comments No comments
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,216 Reputation points

    Hello anonymous user

    Think of Azure as a separate Active Directory site. You can follow the instructions here: to establish site to site VPN connection between Azure and both A and B Forests. Make sure you have conditional forwarding or stub zone configured in DNS of Forest A so that the requests to resolve the FQDN of Forest B can be forwarded to the DCs in that forest. Since you already have forest trust between these forests, you must already have DNS configured with conditional forwarding or stub zone. Make sure the same is present on Azure DCs as well so that any VM trying to resolve FQDN of forest B, can be forwarded to appropriate DCs via the DNS servers in forest A.


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful