    We have a single active directory domain ( We need to setup a
    second domain that will be accessed from the outside for non-employee users
    ( If we do not want the domain to have any access
    to the domain, shouldn't we create a "Domain in a new forest?"

    Creating a "Child domain in an existing domain tree," or a "Domain tree in
    an existing forest" will allow a two way trust between the root domain and
    the child domain correct?
    jktat, Dec 4, 2009
  2. Howdie!
    Yeah, you should create a new forest for this. The security boundary is
    the forest, not the domain.

    What type of access do they need, then? Why would you need to
    authenticate them? What services do they access?

    Florian Frommherz [MVP], Dec 4, 2009
    Not sure how this works yet, but we have a medical system that will
    automatically add users to this new domain(forest) so that they can access
    their medical info and billing online. Thanks for your reply.

    jktat, Dec 4, 2009
