Security in depth · Unit 24 · Lesson 10 of 14
A trust is not universal permission
Read trust direction separately from the permissions on a resource across that boundary.
Helpful before thisActive Directory
After this lesson you can
- Explain why accepted authentication from a trusted forest does not grant an unapproved resource operation.
Recognizing a visitor's identity is different from handing that visitor every key.
Name both sides
In a one-way forest trust, the trusting forest can accept identities from the trusted forest under the configured conditions. Thus “Cedar trusts Harbor” supports Harbor identities being recognized for Cedar resources, not the reverse relationship.
Direction, trust type, and authentication restrictions matter. Resource permissions still determine allowed operations. A forest trust also does not automatically extend through another forest trust to every third organization.
Supplied record: two community centers
The fictional centers operate separate forests, Cedar and Harbor. Their agreement permits selected collaboration.
Trust record: Cedar trusts Harbor in one direction.
Identity: Lia belongs to Harbor.
Authentication evidence: Lia’s identity is accepted at the Cedar archive service.
Current resource decision: Lia has no archive-read grant.
Owner approval: collaboration does not include unrestricted archive access.
Assume connectivity and applicable authentication conditions already succeed. The resource decision includes current memberships, with no other grant or privileged override. Lia’s archive read is therefore unauthorized even though authentication succeeded. A broader resource permission is not implied by the collaboration agreement.
Separate the proposed changes
Write one sentence about identity recognition and another about archive permission. If Lia needs a particular collection, the archive owner must evaluate that purpose and its narrow access requirements. There is no demonstrated need to expand the trust just because this read was denied.
The packet says nothing about reverse access or a third forest. Record those as separate questions rather than turning a one-way relationship into a universal map. Microsoft’s linked explanation includes managed-domain details; this exercise uses only its general trust-direction and resource-permission concepts.
Check yourself
No timer. No penalties. Read the explanation and try again whenever you like.
This lesson’s questions have changed. Your reading progress is saved; review the updated questions.
-
Cedar accepts Lia’s Harbor identity, but the archive grants her no read permission. What follows?
Show the answer
Correct answer: Authentication can succeed while the archive read remains unauthorized under its own policy. The trust enables the accepted identity relationship. The supplied resource permission decision still lacks the required read grant.
Try it
- WriteWrite a direction sentence naming the trusting and trusted forests, then a separate access decision for Lia. Identify the missing resource approval without assuming reverse or third-forest access.