Deploying components of System Center Orchestrator in different domains/forests without trusts

Bojan Zivkovic 551 Reputation points
2025-04-22T11:37:10.0733333+00:00

Hi, is it possible to deploy components of System Center Orchestrator in different domains/forests without trusts between them by doing some extra configuration steps? I have 3 forests completely isolated to one another hence I would like to know if automation of service requests (Web Front End app using Orchestrator Web Service to pass input parameters to Orchestrator Runbook) can work at all in environments like this. Service account Web Front End app IIS App Pool is running under must be an Orchestrator Admin and obviously in absence of trust that cannot be set up, so I am thinking of potentially placing some SCO components in the same forest/domain where Web Front End app instance is hosted whereas having some other components in untrusted forests - awful design but that is a price of not having forest trusts in place.

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,575 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.