cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
595
Views
0
Helpful
3
Replies

ACS and two Windows Active Directory Domains

ursshared
Level 4
Level 4

Can one ACS server authenticate users against two different AD domains? The server is a member server of one domain. We are not able to enumerate the groups from the second domain. There is a two way trust between the domains.

3 Replies 3

Ivan Martinon
Level 7
Level 7

Is there a 2 way trust with the two domains, have you checked that the user that ACS uses to read and query the Domains lies on both domains and has read privileges?

frbilbrey
Level 1
Level 1

We authenticate multiple domains like this, We have a proxy domain that contains the acs remote agents. The proxy domain trusts the domains to be authenticated against. In ACS you will be able to see all of the domains that the proxy trusts. When you go about mapping domain groups to acs groups you have to manually add the group name. ACS can enumerate the group to authenticate users, but ACS cannot seem to traverse multiple domains during the setup phase. Hope this helps.

Bob

are the users in multiple groups in the multiple domains, if so mapping should be done differently than you would if users were in a single group so that users are properly mapped to a group

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: