StudyToCert

All certifications / AZ-802 / Lessons

Microsoft Certified: Windows Server Administrator Associate (exam AZ-802: Administering Windows Server) AZ-802 · Domain 1: Deploy and manage AD DS

Forest, external, shortcut and realm trusts; transitivity and direction; selective authentication; SID filtering

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

A trust is a relationship that lets users in one domain authenticate to resources in another. Trust vocabulary is directional and easy to mix up, so learn it precisely. The trusting domain holds the resources; the trusted domain holds the accounts. Access flows opposite to the trust direction: if Domain A trusts Domain B, users in B can be granted access to resources in A. A two-way trust is simply two one-way trusts. Inside a forest, every domain automatically has two-way transitive parent-child and tree-root trusts, so you only create trusts manually for other forests, other domains outside the forest, or non-Windows Kerberos realms.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study AZ-802 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the AZ-802 study plan