Here are some steps to follow to troubleshoot Active Directory trust relationship issues:
- Collect an inventory of each domain: Identify the domains participating in trust relationships and capture their version, local DNS configuration, IP address, and any other information about the environment.
- Check user and computer accounts: Verify that (1) the accounts that need to be trusted have permissions and passwords, (2) match the namespace in each domain, and (3) are connecting to the correct domain.
- Check DNS and Active Directory configuration settings: Verify that the DNS entries are correctly configured in the active directory and the corresponding zone files have the correct records quoted. Additionally, you may want to check DNS forwarding settings.
- Verify network connectivity: Ensure that the firewalls are permitting proper communication to the active directory. Check ping responses and packet response time to confirm that the server is reachable.
- Run a diagnostic tool: Utilize a trust diagnostics tool to further test the trust relationship; these tools are available from Microsoft, or other trusted sources.