Share via

Trusts - TDO Object

Chrisagardner63 1 Reputation point
2020-09-30T16:39:36.983+00:00

When creating a Active Directory Trust - I have the TDO object in the Systems container.

I am getting some pushback back from our Risk Management team on the objects in the Users container. I believe these are only used when creating the Trust and when the TDO is created, and validated and can be deleted.

Are the objects in the Users Container still needed? The reasoning is that these accounts have the Password Not Expired attribute not set. I cannot find any MS documentation if these User objects can be deleted since the TDO is active in the Systems container.

Any help is appreciated.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments

3 answers

Sort by: Most helpful
  1. Vicky Wang 2,741 Reputation points
    2020-10-12T08:26:43.373+00:00

    Hi,
     
    Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.
     
    Best Regards,
    Vicky

    Was this answer helpful?

    0 comments No comments

  2. Vicky Wang 2,741 Reputation points
    2020-10-01T08:58:01.67+00:00

    >>Are the objects in the Users Container still needed?

    According to my knowledge, does not affect deletion and change

    Hope this information can help you

    Best wishes
    Vicky

    Was this answer helpful?

    0 comments No comments

  3. Thameur-BOURBITA 36,531 Reputation points Moderator
    2020-09-30T18:46:15.03+00:00

    Hi,

    If the account has been used to create the trust , you can delete or modify it it if the trust is already created with no impact on trust and TDO object.

    Please don't forget to mark this reply as answer if it help you to fix your issue

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.