Windows Server 2003
1821587 Members
3763 Online
109633 Solutions
New Discussion юеВ

AD Forest vs Domain

 
SOLVED
Go to solution
Alex Hose
Advisor

AD Forest vs Domain

What is the difference between a AD forest and AD domain?

Specifically, what are the restrictions to the user accessing the resources within the same forest vs accessing the resources in different forest.

2 REPLIES 2

Re: AD Forest vs Domain

Thomas Bianco
Honored Contributor
Solution

Re: AD Forest vs Domain

a Domain is a specific security authority.

domains, usually defined by a DNS name (MYDOMAIN.MYCOMPANY.ORG), contain OU's, User and computer Accounts, and GPO's. some of the FSMO's are domain specific, like PDCEmu.

a Tree is a group of connected domains, in the above example, Mydomain is a member (branch) of the Mycompany tree. all members of a tree trust each other, but other then that they're nothing special.

a forest is a group of 1 or more trees, that all share the same network (landscape) and Schema (growth rules). tree's need not trust eachother, but it really helps if they do. Multi-tree forests are discouraged, and multiforest companies are outright wrong.

hope this helps
There have been Innumerable people who have helped me. Of course, I've managed to piss most of them off.