Kerberos and Separate Active Directory Forests

Kerberos authentication in AD forests is dependent on a forest root trust.

John Savill

March 29, 2013

1 Min Read
Kerberos and Separate Active Directory Forests

Q: Can Kerberos work across separate Active Directory forests?

A: Yes. If a forest root trust is created between the separate Active Directory (AD) forests, then Kerberos authentication is possible between any domain in any forest because of the transitive nature of the forest root trust. It is very important that services such as DNS are also correctly configured for cross-forest authentication to correctly function. The forest level of both forests must be at least Windows Server 2003. See this Microsoft article for some key details.

About the Author

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like