- Home
- Interview Questions
- DNS and Active Directory
- Administrative inconsistency
- Increased management challenges
- Decreased flexibility
Security-related modifications are replicated within a site immediately. These changes include account and individual user lockout policies, changes to password policies, changes to computer account passwords, and modifications to the Local Security Authority (LSA).
Cross-forest trusts are used to share resources between forests. They can only be used with Windows Server 2003 domains and cannot be intransitive, but they can be established in a one-way or two-way configuration. Authentication requests in either forest can reach the other forest in a two-way cross-forest trust.
We use realm trusts to connect to a non-Windows domain that uses Kerberos authentication. Realm trusts can be transitive or non-transitive, one-way or two-way.
Use netdom query /domain:YourDomain FSMO command. It will list all the FSMO role handling domain controllers.