SOLVED

Trust relationship between forests

%3CLINGO-SUB%20id%3D%22lingo-sub-1302752%22%20slang%3D%22en-US%22%3ETrust%20relationship%20between%20forests%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1302752%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Team.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20hava%20a%20AD%20Connect%20synchronizing%20one%20forest.%20Need%20add%20new%20forest%20to%20same%20AD%20Connect.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20kind%20of%20trusth%20relationship%20do%20I%20have%20to%20make%20between%20the%20two%20forest%20for%20AD%20Connect%20synchronize%20the%20objects%20in%20new%20forest%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1302752%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EADConnect%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1320522%22%20slang%3D%22en-US%22%3ERe%3A%20Trust%20relationship%20between%20forests%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1320522%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F392602%22%20target%3D%22_blank%22%3E%40CarlosMoralesMX%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20the%20past%2C%20I%20have%20done%20this%20for%20one%20of%20my%20global%20customers%20by%20ensuring%20that%20there%20is%20some%20sort%20of%20VPN%20connectivity%20between%20the%20two%20AD%20forests%2C%20and%20then%20adding%20a%20secondary%20DNS%20zone%20for%20the%20new%20domain%20to%20be%20synced%20on%20the%20AADC%20server.%20%26nbsp%3BThe%20AADC%20server%20was%20deliberately%20not%20domain%20joined%20in%20this%20scenario.%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOnce%20the%20above%20was%20in%20place%2C%20the%20AADC%20wizard%20was%20run%20again%2C%20and%20a%20new%20ADDS%20connector%20added%20for%20the%20new%20domain.%20%26nbsp%3BWorks%20really%20well.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi Team.

 

I hava a AD Connect synchronizing one forest. Need add new forest to same AD Connect.

 

What kind of trusth relationship do I have to make between the two forest for AD Connect synchronize the objects in new forest?

 

Thanks

1 Reply
best response confirmed by CarlosMoralesMX (Contributor)
Solution

@CarlosMoralesMX 

 

In the past, I have done this for one of my global customers by ensuring that there is some sort of VPN connectivity between the two AD forests, and then adding a secondary DNS zone for the new domain to be synced on the AADC server.  The AADC server was deliberately not domain joined in this scenario.  

 

Once the above was in place, the AADC wizard was run again, and a new ADDS connector added for the new domain.  Works really well.