2.17. Creating a Shortcut Trust Between Two AD Domains
You want to create a shortcut trust between two AD domains in the same forest or in different forests. Shortcut trusts can make the authentication process more efficient between two domains in a forest.
Using a graphical user interface
Open the Active Directory Domains and Trusts snap-in.
In the left pane, right-click the domain you want to add a trust for, and select Properties.
Click on the Trusts tab.
Click the New Trust button.
After the New Trust Wizard opens, click Next.
Type the DNS name of the AD domain and click Next.
Assuming the AD domain was resolvable via DNS, the next screen will ask for the Direction of Trust. Select Two-way and click Next.
For the Outgoing Trust Properties, select all resources to be authenticated and click Next.
Enter and retype the trust password and click Next.
Click Next twice.
Using a command-line interface
> netdom trust <
/Twoway /ADD[RETURN] [/UserD:<
Domain2AdminUser> /PasswordD:*][RETURN] [/UserO:<
To create a shortcut trust from the emea.rallencorp.com domain to the apac.rallencorp.com domain, use the following
> netdom trust emea.rallencorp.com /Domain:apac.rallencorp.com /Twoway /ADD[RETURN] /UserD:email@example.com /PasswordD:*[RETURN] /UserO:firstname.lastname@example.org /PasswordO:*
Consider the forest in Figure 2-6. It has five domains in a single domain tree. ...