Nov 22, 2011

The difference between “new domain tree root” and “new child domain”?


I have 2 Windows 2008 R2 servers. One already has AD and DNS installed. It was set up as a new tree in a new forest.

Now I have to add the second server, which is to have a dns zone that the first server is delegating. The first server is and the second server will be

During the setup, I choose “existing forest”. It’s not an extra domain controller, so I choose “create new domain in existing forest”. Then I saw the option” Create a new domain tree root instead of a new child domain”.

And it has me puzzled, because I don’t know what the implications will be.

I used all my skills in MS Paint to create this diagram representation of the scenario: Diagram


I should preface this answer with a comment. I don’t know your infrastructure, so please forgive me if this doesn’t apply. Microsoft doesn’t recommend child domains or separate tree roots for most organizations. The current recommendation is a single AD domain with business units separated by OUs for management. Unless you have a very compelling reason to complicate your AD structure by doing this, I suggest that you rethink your design and evaluate whether or not a single AD domain might be a better fit.


Above is an example of each. There is no explicit trust between the two domains in the 2nd example, There is still an implied trust, though.

You would have to use a trust shortcut between the two, otherwise the forest root would always have to be queried whenever a cross-domain resource request was made.

Related posts:

  1. How to create a dedicated forest root domain?
  2. AD One-Way Trust between Child and Parent Domains
  3. Raising Functional Level of Child Domain
  4. Installing SharePoint to Root or Child domain
  5. Domain Trust Issues

Leave a comment