Active Directory Forest Trust Permissions to create

Anonymous
2020-12-17T12:02:17.203+00:00

Hello Folks,

Our Scenario: 1 forest and 1 domain and we are dividing it in two companies so we are preparing new forest and new domain.

I have a question we are creating active directory forest trust between two companies and i would like to know what permissions we need to create a successful trust.

  • User Account rights and permissions to create a trust between two companies

Once creating a trust we have tom migrate the users,groups and computers from other domain so what permission are required to delegate a user to migrate the objects.

  • ADMT tool will be used to migrate the objects.

Appreciate your feedback !!

Regards,
Arif

Windows for business Windows Client for IT Pros Directory services Active Directory
Windows for business Windows Server Devices and deployment Set up, install, or upgrade
Windows for business Windows Server User experience Other
0 comments No comments
{count} votes

Accepted answer
  1. Youssef Saad 3,416 Reputation points
    2020-12-17T12:34:40.81+00:00

    Hi anonymous user,

    1. To setup the Trust between two forests, you need either a user member of Enterprise Admins or Domain Admins of the root level, or, you can delegate the rights to a simple user.
    2. You can check the following guide: Active Directory Migration Tool (ADMT): Your Essential Guide

    Regards,


    Youssef Saad | New blog: https://youssef-saad.blogspot.com
    Please remember to ** “Accept answer” ** for useful answers, thank you!


1 additional answer

Sort by: Most helpful
  1. Anonymous
    2020-12-18T00:46:35.747+00:00

    HI,
    To set the up the trust between the forest , the user need the administrative privilege, you either use the member of Domain Admins or members with delegated permissions.

    To run the ADMT, users need to be the member of domain admins in both the source forest and target forest. You may decide to create a user specifically for the ADMT Migration, or you may use an existing user e.g. the default administrator account.

    Best Regards,


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.