Area 10 / 12
Trusts & Forest Design
The forest, not the domain, is the real security boundary — and a careless trust erases it. This area enables SID filtering and selective authentication on trusts, reviews trust direction and transitivity, and explains when a separate administrative forest is the right answer.
Start the pathLearning path
0/4 done- 01Hardening AD trusts and forest boundariesWhy the forest — not the domain — is the AD security boundary, and how to lock down trusts with SID filtering, quarantine, and selective authentication.
- 02SID filtering and selective authentication, step by stepConfigure and verify SID filtering, quarantine and selective authentication on AD trusts with netdom and PowerShell, including trustAttributes and events.
- 03Cleaning up SIDHistory after AD migrationsFind, assess and safely remove sIDHistory left over from domain migrations: dangerous SIDs, ACL re-permissioning, staged removal, rollback limits and detection.
- 04ESAE Red Forest vs the enterprise access model in 2026Why Microsoft retired ESAE as the default, what the enterprise access model asks you to build instead, and when a bastion forest or PAM trust still makes sense.