Chris Beams’s Blog

Active Directory and more….

Trust – LSA Tests

Posted by chrisbeams on June 1, 2009

Spotted this on one of the forums , where someone was trying to create a trust between two domains with the same name 🙂


Before the Local Security Authority (LSA) creates the trust, the LSA verifies the consistency of the parameters. Between the new trust partner and all other domains that are in the same forest as the trust partner, the following items must be unique:

•    The NetBIOS name of the domain
•    The fully qualified domain name (FQDN) of the domain
•    The security identifier (SID) of the domain

You cannot create the trust if one of the three items has duplicates.

Leave a comment