ADFS cross domain (one-way trust)


hello,

 

we're having 2 domains (prod , dev), prod trusted dev, dev not trusted prod.

both have working adfs server installed, working internally , externally(internet).

 

when logging in dev adfs machine prod account, tries ldap request our prod domain controller denies request because doesn't trust dev domain.

what's best way go here?

 

thank you,

 

remon

hi,

 

what trust mean, windows trust (forest/domain trust), federation trusts or others? please clarify issue can provide accurate troubleshooting suggestions.

 

if mean windows trust, user comes trusted domain can log trust domain, user comes trust domain cannot log trusted domain. in case, users prod should able log dev.

 

if mean federation trusts, trusts should two-way. if 1 side of federation trust (either account partner or resource partner) not configured or if configured incorrectly administrator either organization, federation trust not created successfully. more information, please refer following microsoft technet article:

 

federation trusts

http://technet.microsoft.com/en-us/library/cc738707(ws.10).aspx

 

regards,

 

forum support

please remember mark replies answers if , unmark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS