Validating domain trusts

In order to create realm trust, users should have Enterprise Admin or Domain Admin permissions for the Windows Server 2003 domain and should have the permissions required for the non-Windows Kerberos version 5 realm.

What this means is that users do not need to explicitly create these trusts nor do they have to perform any configuration or management tasks for the trust relationships.Shortcut trust improves query response performance as well.The Active Directory tool used to create shortcut trust is the Active Directory Domains and Trusts console.In these domain structures, when users located in one forest needed to access resources located in a different forest, an external trust relationship had to be defined between the two domains.External trusts are one-way and non-transitive in nature.

