Setting up a two way trust

Boe Dillard 666 Reputation points
2023-05-03T19:40:45.5766667+00:00

Hello,

It has been a long time since I've set up a trust and I seem to have forgotten something crucial.

I have a brand new DC for a new domain sitting in azure, I created a conditional forwarder to point to the other domain's domain controller. I can now ping my other domain by name from the domain controller of the other domain.

On the other domain controller which is in production, I put a forwarder to point to the other domain. I can now ping the brand new domain by name from the production domain controller.

I've also added the opposite dc as one of the dns server addresses in the network properties.

When I attempt to set up a trust from the new domain, I put in the production domain's name e.g. acme.local, I select forest trust, then select two-way, then select both this domain and the speficied domain,

When I select next, I get

Cannot continue

Cannot create both sides of the trust because a primay domain controller (PDC) for the speficied domain cannot be contacted. The operation failed. The error is : The operation completed sucessfully.

There is no trust listed.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,215 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 44,101 Reputation points
    2023-05-04T15:27:18.1566667+00:00

    Hello,

    Here are some info about the processes and prerequisites, usually the errors are related to permissions, so you should ensure to have validated the Domain Admin permissions.

    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc780479(v=ws.10)

    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc740018(v=ws.10)

    To create a forest trust:

    Open Active Directory Domains and Trusts.

    In the console tree, right-click the domain node for the forest root domain, and then click Properties.

    On the Trust tab, click New Trust, and then click Next.

    On the Trust Name page, type the DNS name (or NetBIOS name) of another forest, and then click Next.

    On the Trust Type page, click Forest trust, and then click Next.

    On the Direction of Trust page, do one of the following:

    To create a two-way, forest trust, click Two-way.

    Users in this forest and users in the specified forest can access resources in either forest.

    To create a one-way, incoming forest trust, click One-way:incoming.

    Users in the specified forest will not be able to access any resources in this forest.

    To create a one-way, outgoing forest trust, click One-way:outgoing.

    Users in this forest will not be able to access any resources in the specified forest.

    Continue to follow the wizard.

    --If the reply is helpful, please Upvote and Accept as answer--