Establishing an external domain trust has many benefits when separate domains need to share services and data. However the convenience of a domain trust comes at a great risk to the entities within each domain. When establishing a domain trust there is two options for defining the way that users from the trusted domain authenticate to the trusting domain.
The first method is called “Domain-wide authentication”. With this method users from the trusted domain are able to access servers, services, shares and files with normal NTFS and share permissions. In my opinion this places the trusting domain at risk of group nesting or permission creep.
The second method is my preferred method. “Selective authentication” takes a “deny all” approach explicitly blocking all access at the server level to all users who are not explicitly granted the “Allowed to authenticate” permission. With this method administrators must grant rights to each system they wish to allow access to in addition to the NTFS and share permissions. It is an extra level and security and may give your domain administrators a little ease when considering the domain trust risks.
To enable selective authentication there are a few prerequisites. The user preforming the action on the trusting domain must be a Domain Admin or an Enterprise Admin. The domain functional level must be set to a minimum of Windows 2003.
To configure selective authentication on an existing trust:
- Open the Active Directory Domains and Trusts snap-in.
- Right click the domain that you wish to configure and click ‘Properties’.
- Click on the ‘Trusts’ tab.
- Select the trust you wish to configure and click the ‘Properties’ button.
- Click the ‘Authentication’ Tab and then click the ‘Selective Authentication’ radio button.
- Click ‘OK’.
- Open the Active Directory Domains and Trusts snap-in.
- Right click the domain that you wish to configure and click ‘Properties’.
- Click on the ‘New Trust’ button.
- While you are walking through the New Trust Wizard you will be prompted for the authentication type. Select ‘Selective Authentication’ and finish the setup.
The last step in this process is to create a Domain Local Group in which you wish to add users from the trusted domain. The users added to this group will be allowed to authenticate to sepcific computers/servers. After the group is created:
- Open the "Active Directory Users and Computers snap-in.
- Navigate the tree and locate the specific computer/server that you with to grant access to.
- Right click on the computer/server object and choose 'Properties'.
- Click on the 'Security' tab.
- Click the 'add' button and search and select the Domain Local Group that you have just created.
- Once back at the 'Security' tab screen, in the lower half, find the "Allowed to Authenticate' permission and check the 'Allow' box.
- Click "Apply'/'OK'.
Microsoft
Posted by
Mike Wright