Share via

Active Directory trust relationship link validation failing between corporate network and newly integrated cloud identity nodes

Lauram Muller 0 Reputation points
2026-06-18T11:31:33.1466667+00:00

We are establishing a secure Active Directory federation link between our local local domain nodes and a secondary hybrid vendor domain environment. The connection wizard finishes with success, but running cross-domain group membership checks drops a trust verification failure.

Windows for business | Windows 365 Enterprise
0 comments No comments

1 answer

Sort by: Most helpful
  1. Harry Phan 22,550 Reputation points Independent Advisor
    2026-06-18T13:50:38.8366667+00:00

    Hi Lauram,

    Basically, the setup went through fine, but the trust check is failing because the two domains aren’t fully recognizing each other’s security rules. This usually happens when one side blocks how group memberships are shared across the link. To fix it, both domains need to confirm that the trust is marked as “validated,” that DNS lookups work both ways, and that the vendor’s hybrid system isn’t filtering out the group information. Until those settings are aligned, any test of group membership between the two environments will keep failing.

    Harry.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.