Management trust to the tenants.
been thinking bit.. is valid solution: lets i'm working @ cloud provider hosts , manage company's active directory's. tenant have own forest. have each domain admin account in forest. valid/good solution have "management trust"; administrators have accounts, instead of accounts in domain. or there better way manage it? "technically", can create domain/forest trust , provide domain permission. acceptable tenants? though, domain trust doesn't provide permission default, don't want see company's trust in ad domain. santhosh sivarajan | houston, tx | www.sivarajan.com itil,mcitp,mcts,mcse (w2k3/w2k/nt4),mcsa(w2k3/w2k/msg),network+,ccna my books: | windows server security | windows server 2012 blogs | twitter | linkedin | facebook | posting provided no warranties, , confers no rights. Windows Server ...