All lessons Leer en español

Security in depth · Unit 24 · Lesson 10 of 14

A trust is not universal permission

Read trust direction separately from the permissions on a resource across that boundary.

4 minreadyShort lesson

Helpful before thisActive Directory

See all lessons in this topic

After this lesson you can

  • Explain why accepted authentication from a trusted forest does not grant an unapproved resource operation.

Recognizing a visitor's identity is different from handing that visitor every key.

Name both sides

In a one-way forest trust, the trusting forest can accept identities from the trusted forest under the configured conditions. Thus “Cedar trusts Harbor” supports Harbor identities being recognized for Cedar resources, not the reverse relationship.

Direction, trust type, and authentication restrictions matter. Resource permissions still determine allowed operations. A forest trust also does not automatically extend through another forest trust to every third organization.

Identity recognition → Trust conditions → Resource permissionsIdentity recognitionTrust conditionsResource permissions
This is a list of contributing decisions, not a diagram of trust direction. Name the trusting side, trusted side, and resource authorization separately.

Supplied record: two community centers

The fictional centers operate separate forests, Cedar and Harbor. Their agreement permits selected collaboration.

Trust record: Cedar trusts Harbor in one direction.
Identity: Lia belongs to Harbor.
Authentication evidence: Lia’s identity is accepted at the Cedar archive service.
Current resource decision: Lia has no archive-read grant.
Owner approval: collaboration does not include unrestricted archive access.

Assume connectivity and applicable authentication conditions already succeed. The resource decision includes current memberships, with no other grant or privileged override. Lia’s archive read is therefore unauthorized even though authentication succeeded. A broader resource permission is not implied by the collaboration agreement.

Separate the proposed changes

Write one sentence about identity recognition and another about archive permission. If Lia needs a particular collection, the archive owner must evaluate that purpose and its narrow access requirements. There is no demonstrated need to expand the trust just because this read was denied.

The packet says nothing about reverse access or a third forest. Record those as separate questions rather than turning a one-way relationship into a universal map. Microsoft’s linked explanation includes managed-domain details; this exercise uses only its general trust-direction and resource-permission concepts.

Check yourself

No timer. No penalties. Read the explanation and try again whenever you like.

  1. Cedar accepts Lia’s Harbor identity, but the archive grants her no read permission. What follows?

    Show the answer

    Correct answer: Authentication can succeed while the archive read remains unauthorized under its own policy. The trust enables the accepted identity relationship. The supplied resource permission decision still lacks the required read grant.

Try it

  • WriteWrite a direction sentence naming the trusting and trusted forests, then a separate access decision for Lia. Identify the missing resource approval without assuming reverse or third-forest access.
References