Quantcast
Channel: All Centrify Express posts
Viewing all articles
Browse latest Browse all 1833

Re: Adding users from other AD domain

$
0
0

,

 

Welcome back.

 

I am going by the example that you just mentioned.  You have added a new parallel forest (not a child domain e.g. north.contoso.com vs south.contoso.com).  Since these two forests are disjointed, you have several options based on your infrastructure or security posture.

 

With AD using a trust relationship:  If both forests (domain1.local and domain2.local) have a transitive two-way trust relationship, the cloud connector will recognize the new forests and will start including users from the newly-trusted forest, however this may not be aligned with your security goals.

 

With Centrify Identity Service adding a cloud connector in a properly sized Windows sytem to provide AD Proxy services to domain2.local.  This way you can pick users, sync identities, provide SSO and provisioning for O365 for users from both forests.

 

Check the cloud connector help for more info:  https://docs.centrify.com/en/centrify/adminref/index.html?version=141#page/cloudhelp%2Fcloud-admin-config-proxy.html%23

 

R.P


Viewing all articles
Browse latest Browse all 1833

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>