WIKI / introductory

Trust relationships

Reading Active Directory as a graph of authorisation and administration decisions.

Trust relationships determine how an identity from one context may be recognised or authorised in another. Their impact depends on direction, filtering and effective privileges.

What to relate

Document domains, forests, principals and resources. Distinguish authentication from authorisation: being recognised does not imply receiving access.

Useful questions

  • In which direction does trust flow?
  • Which identities can cross the boundary?
  • Which controls alter the expected behaviour?

Evidence

Represent every relationship with its origin and conditions. Do not infer impact from the existence of a trust alone.