UPN Suffixe and Forest Trust (same domain name)
hi,
we have 2 domains : 1 old (let's call domainold.local) , 1 new (let's newdomain.local) forest trust between them. users migrating new domain.
we set alternative upn suffixe in newdomain (newdomain.local) using old domain name (domainold.local) to allow users logon it. note : users have new sam name in new domain.
but have declared trust same dns name (domainold.local) between 2 forests.
so question : can add alternative upn "domainold.local" in "newdomain.local" if have active trust "domainold.local" ? need sure adding upn not interfere trust or not block use of old domain accounts new domain.
hope i'm clear enough :) thanks.
simple answer no, cause name collision. reason if users logging in while connected new domain old domain's account, authentication not passed through.
if dissolve trust, yes.
ace fekay
mvp, mct, mcitp/ea, mcts windows 2008/r2 & exchange 2007, exchange 2010 ea, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services
technical blogs & videos: http://www.delawarecountycomputerconsulting.com/
this post provided as-is no warranties or guarantees , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment