Domains, Trees, Forests Domains, Trees & Forests Every Domain is part of a Tree, is part of a Forest (even a single domain) Domains which share the parent domain name belong to the same tree Trust Relationships connect domains Forest Root (Root Domain) - First domain, cannot change Enterprise admins control entire forest Domain admins control their domain Trees later merged via forest trust will share resources but not schema Global catalogue is replicated across the whole forest Trusts Trust Relationships can have a Two-way transitive trust (follows through to sub-domains) One-way directional trust Shortcut trust (can be either of the above) (two or one way) Forest trust - between two forests (unlike below) (two or one way)  Realm trust - Unix/Linux Realm (Kerberos) Setup via Active Directory Domains and Trusts Configure DNS to ensure they can communicate (conditional forwarders) KCC Knowledge consistency checker - all D.Cs have it Creates a circular ring of trust between D.Cs in close proximity (latency) within the same site (intrasite replication) Updates based on D.C. Availbility, checks every 15 minutes Separation of sites frees up bandwidth. KCC Creates new rings within each site and appoints one D.C. as a Bridge Head (every 180 minutes) (can be altered) (Inter-Site Replication) Site Links Redundant site links are setup, each have a cost (default 100) Adjust cost based on primary and secondary links IP Addresses are set such that devices interact with their local D.C. (Subnets) Site link bridging can be setup based on a hierarcy (default all on) May wish to disable site link bridging where a site has multiple sub-sites Configured and Managed via AD DS > Sites