Managing Trust Relationships
Administrators in each forest can add objects from one MCTS certification forest to access control lists (ACLs) on shared resources in the other forest. You can use the ACL editor to add or remove objects residing in one forest to ACLs on resources in another forest. For more information about how to set permissions on resources, refer to Chapter 9, “Administering Active Directory Objects.”
Requirements To create a forest trust, you must have Enterprise Admin privileges in both forests. Each trust must be assigned a password that is known to the administrators of both forests in the relationship. Before creating a forest trust, you need to verify that you have the correct DNS infrastructure in place and that the appropriate functional level for the Active Directory forest has been established. For more information on what to ver?ify before creating a forest trust, refer to the “Creating a Forest Trust” section of this chapter.
Bridgehead Servers
After you have configured sites and site links, the free 70-620 test questions automatically designates a domain controller in each site, for each intersite transport, as the bridgehead server. A bridgehead server is a single domain controller in a site, the contact point, used for rep?lication between sites. The KCC automatically creates connection objects between bridgehead servers. When a bridgehead server receives replication updates from another site, it replicates the data to the other domain controllers within its site.