Page 1 of 1

Integrated Login across domains

Posted: Tue Sep 23, 2008 9:44 pm
by mmsantiago
Hi everyone,
I have a quick question about integrated login. We currently have users in two different domains that are connecting to a TM1 server existing on one of the domains. When the users connect directly, not using integrated login, there are no problems. When we switch to integrated login, however, those users who exist on a different domain than the server are unable to connect successfully. Knowing very little about how domains communicate, I am assuming this is expected behavior, but is there a way around it short of moving users on domain Y to domain X where the TM1 server resides?

Appreciate any assistance.

Re: Integrated Login across domains

Posted: Wed Sep 24, 2008 6:56 am
by jim wood
Hello there,

Basically each domain has whats called an active directory. This is domain specific. Within it are whats called "LDAP Conatainers". These containers hold the user information used within direct connection. The people on the same domain as the server will be ok as their details will be held within the container. Those on the other domain are not so lucky as their details will not be held. You may be able to get round this by speaking to your IT department. I think it's possible to create a mapping that means those from th other domain will be registered on the other domains directory. I'm completly certain this is possible. Have a chat with your IT guys and see what they say. I hope this helps,

Jim.

Re: Integrated Login across domains

Posted: Wed Sep 24, 2008 10:24 am
by mattgoff
It's definitely possible as long as the domains are in the same AD forest and that forest is set up correctly. We have three domains logging into a TM1 daemon running under a user account in one of the domains.

Matt

Re: Integrated Login across domains

Posted: Fri Sep 26, 2008 4:08 pm
by mmsantiago
Sounds like my next step is to talk to IT. Thank you both for your responses!

Best Regards,