Apply the root-domain step before Azure Files cloud-trust child-domain setup

Review the documented multi-domain sequence before retrying a Trusted Domain Object creation error.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

Review the documented multi-domain sequence before retrying a Trusted Domain Object creation error.

Potentially affected

Multi-domain AD forests configuring the documented Azure Files cloud trust with Microsoft Entra ID.

DSE recommendation

Identify the forest root and child domains, then verify the documented SetupCloudTrust sequence before retrying the operation.

Source facts

For a multi-domain forest, Microsoft’s Azure Files cloud-trust guidance says to run the root-domain operation with SetupCloudTrust, then run the child-domain operation without that parameter. It identifies this sequence as a way to avoid LsaCreateTrustedDomainEx error 0x549 on a child domain.

The guidance supports forest trusts for Azure Files, not external trusts. Its hybrid-user scenario uses on-premises AD identities synchronized into Entra ID. Microsoft Learn.

Applicability

Use this narrow sequencing check within an otherwise approved cloud-trust deployment. Review the full source’s client, synchronization, permission, storage, and authentication prerequisites separately; this article is not a complete trust-creation procedure.

DSE recommendation

DSE recommends recording the forest-root domain, each intended child domain, and the current Kerberos/trust configuration before retrying a failed command. Have the directory owner verify which operation already succeeded. Keep privileged credentials out of command transcripts and use the established identity-change approval process.

Verification

In a representative authorized test, inspect the resulting cloud-trust configuration after the root and child steps. Test the intended user’s Azure Files authentication and access, and preserve sanitized error codes and domain scope. Do not use disappearance of the creation error as the only evidence that the complete file-access path works.

Official references

Microsoft Learn: Configure Cloud Trust between AD DS and Entra ID. Source retrieved September 9, 2026.

Primary reference

Review the official source

Configure Cloud Trust between AD DS and Entra ID | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE