Active Directory Domain referrals / domain realm mapping

Dolcino 21 Reputation points

Hi, I would like to ask that how active directory domain referral works.

Concept "referral" comes from kerberos, refer to

I built up a cross-realm trusts between Windows AD and MIT Kdc5.

In MIT Kdc, the way referral works is storing domain_realm mapping at KDC's krb5.conf. Refer to

When client query a server in another domain, KDC will tell client which domain that server is in, if that server host name match domain_realm mapping at KDC's krb5.conf.

However, I don't know how that works at windows AD.
1> How referral works at Windows AD
2> How I can set domain realm mapping at windows AD.

Thanks for your help.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
4,305 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 37,746 Reputation points

    Hello @Dolcino

    Referrals are not a very easy task to explain, due to the length of their interaction with your domain.

    I would recommend the next readings to understand how domain referral works, and with information on how to manage them:

    Hope this provides more information about what you want to achieve,
    Best regards,

    0 comments No comments