Skip to main content

Cross Forest Resource Security

Cross-forest resource security 

 

To grant access to resources from one forest to another: 

  1. Create/ensure they have a forest level transitive trust 

  2. Create a domain local security group 

    1. This group will be what is assigned to the resources. 

    2. File shares, delegated AD permissions, etc should point to the domain local group 

  3. Create a universal security group 

    1. This will be what the users are added to 

  4. Assign the universal groups as a member of the domain local groups