# Apply the root-domain step before Azure Files cloud-trust child-domain setup

> Review the documented multi-domain sequence before retrying a Trusted Domain Object creation error.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-182-apply-the-root-domain-step-before-azure-files-cloud-trust-child-domain-setup/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:54+00:00
- Modified: 2026-09-10T00:55:36+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Review the documented multi-domain sequence before retrying a Trusted Domain Object creation error.

## Potentially affected

Multi-domain AD forests configuring the documented Azure Files cloud trust with Microsoft Entra ID.

## DSE recommendation

Identify the forest root and child domains, then verify the documented SetupCloudTrust sequence before retrying the operation.

## Article

## Source facts

For a multi-domain forest, Microsoft’s Azure Files cloud-trust guidance says to run the root-domain operation with SetupCloudTrust, then run the child-domain operation without that parameter. It identifies this sequence as a way to avoid LsaCreateTrustedDomainEx error 0x549 on a child domain.

The guidance supports forest trusts for Azure Files, not external trusts. Its hybrid-user scenario uses on-premises AD identities synchronized into Entra ID. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/files/storage-files-identity-auth-hybrid-cloud-trust).

## Applicability

Use this narrow sequencing check within an otherwise approved cloud-trust deployment. Review the full source’s client, synchronization, permission, storage, and authentication prerequisites separately; this article is not a complete trust-creation procedure.

## DSE recommendation

DSE recommends recording the forest-root domain, each intended child domain, and the current Kerberos/trust configuration before retrying a failed command. Have the directory owner verify which operation already succeeded. Keep privileged credentials out of command transcripts and use the established identity-change approval process.

## Verification

In a representative authorized test, inspect the resulting cloud-trust configuration after the root and child steps. Test the intended user’s Azure Files authentication and access, and preserve sanitized error codes and domain scope. Do not use disappearance of the creation error as the only evidence that the complete file-access path works.

## Official references

[Microsoft Learn: Configure Cloud Trust between AD DS and Entra ID](https://learn.microsoft.com/en-us/azure/storage/files/storage-files-identity-auth-hybrid-cloud-trust). Source retrieved September 9, 2026.

## Primary reference

- Name: Configure Cloud Trust between AD DS and Entra ID | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/files/storage-files-identity-auth-hybrid-cloud-trust
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Apply the root-domain step before Azure Files cloud-trust child-domain setup,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-182-apply-the-root-domain-step-before-azure-files-cloud-trust-child-domain-setup/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
