Home

Tree AD trust with AAD Connect

%3CLINGO-SUB%20id%3D%22lingo-sub-844825%22%20slang%3D%22en-US%22%3ETree%20AD%20trust%20with%20AAD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-844825%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20guys.%20I%20have%20a%20customer%20having%20multiple%20forests%20but%20one%20of%20them%20is%20tree%20root%20trust%20and%20not%20forest%20trust.%20We%20implemented%20AAD%20Connect%20and%20we%20can't%20synchronize%20user%20password%20with%20this%20forest.%20All%20accounts%20in%20other%20forests%20work%20very%20well.%3C%2FP%3E%3CP%3ESomeone%20knows%20if%20the%20tree%20root%20trust%20is%20compatible%20with%20Azure%20AD%20Connect%20%3F%20Someone%20already%20has%20this%20problem%20%3F%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-844825%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%20Connect%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-847274%22%20slang%3D%22en-US%22%3ERe%3A%20Tree%20AD%20trust%20with%20AAD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-847274%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F244938%22%20target%3D%22_blank%22%3E%40mathiassii%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAD%20trust%20is%20not%20a%20requirement%20for%20AAD%20Connect%20unless%20you%20are%20using%20PTA%20for%20auth.%20If%20using%20PTA%20you%20will%20need%20a%20forest%20trust.%20If%20not%20using%20PTA%20then%20check%20if%20the%20permissions%5Cfirewalls%20are%20all%20in%20place%20for%20password%20sync.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CFONT%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-pta-faq%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-pta-faq%3C%2FA%3E%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-847286%22%20slang%3D%22en-US%22%3ERe%3A%20Tree%20AD%20trust%20with%20AAD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-847286%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F8188%22%20target%3D%22_blank%22%3E%40Lavanya%20Murthy%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECurrently%20we%20didn't%20implement%20the%20PTA%20but%20it's%20the%20next%20step%20%3B).%20Thanks%20for%20your%20link.%3C%2FP%3E%3CP%3EWe%20will%20recheck%20the%20permissions%20and%20firewall.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-847514%22%20slang%3D%22en-US%22%3ERe%3A%20Tree%20AD%20trust%20with%20AAD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-847514%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F244938%22%20target%3D%22_blank%22%3E%40mathiassii%3C%2FA%3E%26nbsp%3B%20The%20ADDS%20connector%20space%20agent%20needs%20to%20have%20at%20least%20the%20following%20permissions%20in%20the%20other%20forest.%20Did%20you%20verify%20this%3F%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-configure-ad-ds-connector-account%23permissions-for-password-hash-synchronization%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-configure-ad-ds-connector-account%23permissions-for-password-hash-synchronization%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CTABLE%3E%3CTBODY%3E%3CTR%3E%3CTD%3EAllow%3C%2FTD%3E%3CTD%3EAD%20DS%20Connector%20Account%3C%2FTD%3E%3CTD%3EReplicating%20Directory%20Changes%3C%2FTD%3E%3CTD%3EThis%20object%20only%20(Domain%20root)%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3EAllow%3C%2FTD%3E%3CTD%3EAD%20DS%20Connector%20Account%3C%2FTD%3E%3CTD%3EReplicating%20Directory%20Changes%20All%3C%2FTD%3E%3CTD%3EThis%20object%20only%20(Domain%20root)%3C%2FTD%3E%3C%2FTR%3E%3C%2FTBODY%3E%3C%2FTABLE%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-849985%22%20slang%3D%22en-US%22%3ERe%3A%20Tree%20AD%20trust%20with%20AAD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-849985%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F274560%22%20target%3D%22_blank%22%3E%40rosaliod%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eyes%20we%20verified%20it%20and%20everything%20is%20ok.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-850120%22%20slang%3D%22en-US%22%3ERe%3A%20Tree%20AD%20trust%20with%20AAD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-850120%22%20slang%3D%22en-US%22%3EYou%20mentioned%20an%20AD%20Tree%20trust%20however%20there%20are%20only%204%20types%20of%20trusts%20I%20know%20of.%3CBR%20%2F%3E%3CBR%20%2F%3E1.external%20trust%3CBR%20%2F%3E2.%20Realm%20trust%3CBR%20%2F%3E3.%20Forest%20trust%3CBR%20%2F%3E4.%20Shortcut%20trust%3CBR%20%2F%3E%3CBR%20%2F%3EWhich%20trust%20is%20configured%3F%20Is%20this%20a%20domain%20in%20the%20same%20Forest%20or%20a%20domain%20in%20another%20Forest%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-850160%22%20slang%3D%22en-US%22%3ERe%3A%20Tree%20AD%20trust%20with%20AAD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-850160%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F244938%22%20target%3D%22_blank%22%3E%40mathiassii%3C%2FA%3E%26nbsp%3BI%20recommend%20you%20try%20using%20the%20password%20hash%20troubleshooting%20tool.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Ftshoot-connect-password-hash-synchronization%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Ftshoot-connect-password-hash-synchronization%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-851207%22%20slang%3D%22en-US%22%3ERe%3A%20Tree%20AD%20trust%20with%20AAD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-851207%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F274560%22%20target%3D%22_blank%22%3E%40rosaliod%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt's%20the%20first%20time%20i%20heard%20this%20type%20of%20trust%20but%20i%20confirm%2C%20this%20trust%20exists%3C%2FP%3E%3CH3%20id%3D%22toc-hId-1623663580%22%20id%3D%22toc-hId-1623663580%22%20id%3D%22toc-hId-1623663580%22%20id%3D%22toc-hId-1623663580%22%3EActive%20Directory%20Trust%20Types%3C%2FH3%3E%3CP%20align%3D%22justify%22%3E%3CU%3EParent-child%20Trust%3A%3C%2FU%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3EParent-child%20Trust%20is%20an%20implicitly%20established%2C%20two-way%2C%20transitive%20trust%20when%20you%20add%20a%20new%20child%20domain%20to%20a%20tree.%3C%2FP%3E%3CP%20align%3D%22justify%22%3E%3CU%3ETree-root%20Trust%3A%3C%2FU%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3ETree-root%20Trust%20is%20an%20implicitly%20established%2C%20two-way%2C%20transitive%20trust%20when%20you%20add%20a%20new%20tree%20root%20domain%20to%20a%20forest.%3C%2FP%3E%3CP%20align%3D%22justify%22%3E%3CU%3EShortcut%20Trust%3A%3C%2FU%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3EShortcut%20Trust%20is%20an%20explicitly%20created%2C%20transitive%20trust%20between%20two%20domains%20in%20a%20forest%20to%20improve%20user%20logon%20times.%20Shortcut%20Trust%20will%20make%20a%20trust%20path%20shorter%20between%20two%20domains%20in%20the%20same%20forest.%20The%20Shortcut%20Trust%20can%20be%20one-way%20or%20two-way.%3C%2FP%3E%3CP%20align%3D%22justify%22%3E%3CU%3EExternal%20Trust%3A%3C%2FU%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3EExternal%20Trust%20is%20explicitly%20created%2C%20non-transitive%20trust%20between%20Windows%20Server%202003%20domains%20that%20are%20in%20different%20forests%20or%20between%20a%20Windows%20Server%202003%20domain%20and%20Windows%20NT%204%20domain.%20The%20External%20Trust%20can%20be%20one-way%20or%20two-way.%3C%2FP%3E%3CP%20align%3D%22justify%22%3E%3CU%3ERealm%20Trust%3A%3C%2FU%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3ERealm%20Trust%20is%20explicitly%20created%20transitive%20or%20non-transitive%20trust%20between%20a%20non%20Windows%20Kerberos%20realm%20and%20a%20Windows%20Server%202003%20domain.%20This%20trust%20helps%20to%20create%20trust%20relationship%20between%20Windows%20Server%202003%20domain%20and%20any%20Kerberos%20version%205%20realm.%20The%20Realm%20Trust%20can%20be%20and%20one-way%20or%20two-way.%3C%2FP%3E%3CP%20align%3D%22justify%22%3E%3CU%3EForest%20Trust%3A%3C%2FU%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3EForest%20Trust%20is%20explicitly%20transitive%20(between%20two%20forests)%20created%20trust%20between%20two%20forest%20root%20domains.%20The%20Forest%20Trust%20can%20be%20one-way%20or%20two-way.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-851509%22%20slang%3D%22en-US%22%3ERe%3A%20Tree%20AD%20trust%20with%20AAD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-851509%22%20slang%3D%22en-US%22%3EThat%20sure%20is%20right!%20Did%20you%20get%20a%20chance%20to%20use%20the%20password%20sync%20troubleshooting%20tool%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-870317%22%20slang%3D%22en-US%22%3ERe%3A%20Tree%20AD%20trust%20with%20AAD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-870317%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F274560%22%20target%3D%22_blank%22%3E%40rosaliod%3C%2FA%3E%2C%3C%2FP%3E%3CP%3EWe%20asked%20to%20the%20customer%20if%20he%20did%20something%20because%20today%20it%20works.%3C%2FP%3E%3CP%3EWe%20will%20see%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
mathiassii
Occasional Contributor

Hi guys. I have a customer having multiple forests but one of them is tree root trust and not forest trust. We implemented AAD Connect and we can't synchronize user password with this forest. All accounts in other forests work very well.

Someone knows if the tree root trust is compatible with Azure AD Connect ? Someone already has this problem ?

Thanks

9 Replies

@mathiassii 

 

AD trust is not a requirement for AAD Connect unless you are using PTA for auth. If using PTA you will need a forest trust. If not using PTA then check if the permissions\firewalls are all in place for password sync.

 

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-faq

 

Hi @Lavanya Murthy ,

 

Currently we didn't implement the PTA but it's the next step ;). Thanks for your link.

We will recheck the permissions and firewall.

 

Thanks

@mathiassii  The ADDS connector space agent needs to have at least the following permissions in the other forest. Did you verify this?

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-configure-ad-ds-connec... 

AllowAD DS Connector AccountReplicating Directory ChangesThis object only (Domain root)
AllowAD DS Connector AccountReplicating Directory Changes AllThis object only (Domain root)

Hi @rosaliod 

yes we verified it and everything is ok.

You mentioned an AD Tree trust however there are only 4 types of trusts I know of.

1.external trust
2. Realm trust
3. Forest trust
4. Shortcut trust

Which trust is configured? Is this a domain in the same Forest or a domain in another Forest?

Hi @rosaliod 

 

It's the first time i heard this type of trust but i confirm, this trust exists

Active Directory Trust Types

Parent-child Trust: Parent-child Trust is an implicitly established, two-way, transitive trust when you add a new child domain to a tree.

Tree-root Trust: Tree-root Trust is an implicitly established, two-way, transitive trust when you add a new tree root domain to a forest.

Shortcut Trust: Shortcut Trust is an explicitly created, transitive trust between two domains in a forest to improve user logon times. Shortcut Trust will make a trust path shorter between two domains in the same forest. The Shortcut Trust can be one-way or two-way.

External Trust: External Trust is explicitly created, non-transitive trust between Windows Server 2003 domains that are in different forests or between a Windows Server 2003 domain and Windows NT 4 domain. The External Trust can be one-way or two-way.

Realm Trust: Realm Trust is explicitly created transitive or non-transitive trust between a non Windows Kerberos realm and a Windows Server 2003 domain. This trust helps to create trust relationship between Windows Server 2003 domain and any Kerberos version 5 realm. The Realm Trust can be and one-way or two-way.

Forest Trust: Forest Trust is explicitly transitive (between two forests) created trust between two forest root domains. The Forest Trust can be one-way or two-way.

That sure is right! Did you get a chance to use the password sync troubleshooting tool?

Hi @rosaliod,

We asked to the customer if he did something because today it works.

We will see ;)

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies