- In an AD environment, trust is a relationship between two domains or
forests which allows users of one domain or forest to access resources
in the other domain or forest.
- Trust can be automatic (parent-child, same forest etc.) or established
(forest, external).
- Trusted Domain Objects (TDOs) represent the trust relationships in a
domain.
Trust Direction
- One-way trust – Unidirectional. Users in the trusted domain can
access resources in the trusting domain but the reverse is not true.
Trust Direction
- Two-way trust – Bi-directional. Users of both domains can
access resources in the other domain.
Transitive
Can be extended to establish trust relationships with other domains.
- All the default intra-forest trust relationships (Treeroot, Parent-Child) between domains within a same
forest are transitive two-way trusts.
Nontransitive
Cannot be extended to other domains in the forest. Can be two-way or oneway.
- This is the default trust (called external trust) between two domains in different forests when forests do not have a trust relationship
Default/Automatic Trusts
- It is created automatically between the new domain and the domain that precedes it in the namespace hierarchy, whenever a new domain is added in a tree. For example, dollarcorp.moneycorp.local is a child of moneycorp.local
- This trust is always two-way transitive.
- Tree-root trust
• It is created automatically between whenever a new domain tree is added to a forest root.
• This trust is always two-way transitive.
External Trusts
- Between two domains in different forests when forests do not have a trust relationship.
- Can be one-way or twoway and is nontransitive.
Domain Trust mapping
- Get a list of all domain trusts for the current domain
Get-DomainTrust

Get-ADTrust -Filter *