Cross domain validation


hello

we have domain1 , domain2, different forest.

domain1 has sharepoint server.

they asking us, need users on domain2, access recurses on domain1.

but although want this, want users on domain2, use domain1 logon server, without creating user on domain1.

example:

user peter member of domain2, not of domain1. want peter access recurses on domain1-

peter not exist on domain1. know, federation can able access domain1 recurses validating this: domain2\peter. but, there way, this, validating like: domain1\peter?

the requisite not create user peter on domain1.

i want confirm possible or no, , if there alternative this, or can best option, before telling nothing company.

thanks!

hiya,

no it's not possible. using domain1\john.doe indicates user exists in directory associated domain name, not, if not want create it.

using federated authentication, tell sharepoint server, it's okay use identities domain, if trust identity provider.

the best , option, use federated authentication , user logs on using identity domain2 - either john.doe@domain2.com or ever way setup federation work.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client