You are viewing limited content. For full access, please sign in.

Question

Question

Rio setup with multiple domains

asked on June 7, 2018

I have a customer with the above scenario.  They are currently only using Laserfiche in domain "b.company.com", but have people in the other domains that need to be given access.  I find very little documentation about how to set up AD users in multiple domains.

I know that in LFDS, I would register a new identity provider for each domain (providing credentials for given domain) and that LFDS must be able to contact a Domain Controller for each of the domains.  But is that enough?  When a user from another domain tries to log into the repository in Domain B, does LFS need access to their DC to authenticate them or is that all handled by LFDS?

0 0

Replies

replied on June 7, 2018 Show version history
0 0
replied on June 7, 2018

Thanks, but that still does not answer a lot of my questions.  My customer has a Universal AD group that they are putting users into and that group is then in a synchronization rule in LFDS under their "b.company.com" domain.  If they add "a" and "c" domain users to that "b" domain universal group, will that work or do they still need to set up the identity providers for "a" and "c"?

If they set up identity providers for "a" and "c", do they need synchronization rules under each provider to sync with the "b" domain universal group?

0 0
replied on June 7, 2018

As long as "a" and "c" domain users can be added under "b" domain universal group, then they don't need to set up the identity providers for "a" and "c".

If they set up identity providers for "a" and "c", they don't need to add synchronization rules under each provider if they just want to sync with the "b" domain universal group.

Note:

Domain universal group AD group sync is not supported before LFDS 10.2.0.210

 

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.