child domain and authentication

F

fabiom

I have a root domain (for example alpha.it)

and a child domain (beta.alpha.it)

they are on the same site
(but they will soon be on two separate sites if all goes well)

I can login with user (e-mail address removed) on a machine of domain
beta.alpha.it

and I can see all resources of beta.alpha.it and alpha.it

and is ok.

The second step will be moving beta.alpha.it domain controller and
machines in a branch office connected with adsl.

I will create two sites: one for the subnet where there is domain
controller
and machines of alpha.it and one for the subnet where there will be
domain controller and machines of beta.alpha.it (as the link between
the two locations is slow and i can schedule replication).

now: if I am user: (e-mail address removed) and I move to branch office where
there is
domain beta.alpha.it I should logon and see all resources of both
domains...

(I tried this now that the DC are both in the same site and is ok)

but what if the adsl connction fails?

I tried to simulate this disconnecting ethernet cable of alpha.it DC.

I can logon to the PC of domain beta.alpha.it only because I've done
it before but then I cannot access any resource of domain
beta.alpha.it

If I reconnect the cable than I can access all resources again as if I
needed
an authentication from my DC controller as a grant to access resources
of
beta.alpha.it

Now finally the question:

is there a way to logon to the child domain and see resources of the
child domain logging with a user of the parent domain if the link with
between the parent and child DCs goes down?

I'm a newby of AD
sorry if this question may sound stupid for most of you

Thank you for your help

Fabio
 
J

Jody Flett [MSFT]

Hi Fabio

You will not be able to log on as a user from the Root Domain (alpha.it) if
there is no connection to a Root Domain Controller. A DC in a Child Domain
cannot validate a user from the Root Domain. In order to guarentee that all
Users from all Domains can logon if the site ADSL link goes down you will
need to have a DC from each domain at each location.

You should however be able to Log on and use resources of the child domain
if logged on as a user from the child domain even though the link to the
Root Domain is down. You will need to ensure that the Child DC is also a GC.

I hope I have understood you question and given you the answer you need but
please post back if not...

Thanks

Jody
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top