Getting Started with Campus AD
One-Way Trust Prerequisites: https://docs.google.com/document/d/1pMXxk6xyZykbab2n5oDhp9mMXa_ygGMrrhuNveu703Q/edit
Domain name
Department name
Domain contact
DNS server type (Windows or Other)
IPs for each DNS server in the department domain
ServiceNow Request Form:
Information Technology Services > Advanced Technical Services > Identity and Access > Request Inbound Trust Relationship
Preparing Department Domains to Establish Trust:
Set up Firewall rules on your domain controllers using one of the following two methods:
Import the premade group policy object located on the MAUG github.
ORCreate firewall rules as shown in step 2 of prerequisite document
Double check UTM policies and ACLs to ensure successful connections
Verify Kerberos preauthentication on users in department domain
Create conditional forwarders in department domain DNS for Campus AD
Verify conditional forwarders work using ping/tracert
Establish 1-Way Inbound Trust with Campus AD: https://docs.google.com/document/d/19GoWyRaJK1igMhQQzFSH2sXf8ZLvby213RuNOqRH21Y/edit
Verify conditional forwarders bidirectionally
Create new trust relationship in Campus AD for department domain
Share initial trust password (must match on both sides)
Choose selective auth vs. forest wide authentication https://social.technet.microsoft.com/wiki/contents/articles/50969.active-directory-forest-trust-attention-points.aspx
Test Campus AD user authentication in department domain