That's correct. The domains need to be in the same forest, and you'll need to update the security config JSON to point to your global catalog server.
Hi Folks,
Sorry for late into the party, does any one has resolved this issue or has any documentation on this?
Even at 10.4 - It seems if domains (A and in different forest ArcGIS server does not support this config.
We are also looking into ADLDS as an option. If anyone can provide details and additional information, we'd truly appreciate it!
Jose, I'm not a domain admin, and I'm not sure how this nested group you mention would be configured. Do you recall how you laid this out and can you explain further?
Matej, were you able to deploy AD LDS to resolve this issue? If so, can you explain how you went about configuring ad-lds and some instructions that helped you do so?
Hi Justin,Sorry for the delay but I was gathering more information about the underlying configuration.The configuration is as follows:Domain A and Domain B are not in the same domain forest.Eeach domain serves as a global catalog for themselves.There is one way selective trust between Domain A and Domain B.Is there any way how to use this configuration with ArcGIS for Server?Thanks,Matej
Hi Justin,Yes, we configured ArcGIS Server to use the AGSMembershipProvider.AGSADMembershipProvider and AGSMembershipProvider.AGSADRoleProvider according the web help.However, having done that, we still cannot login to ArcGIS Server using credentials from the second domain.Let me describe our configuration.We have AGS running in domain A.Users from domain A can login to ArcGIS Server (using either Windows authentication or the membership and role providers mentioned above).We have domain B and we need to allow users from domain B to login to ArcGIS Server.So we created group A in domain A with nested group B from domain B.Users from domain B which need access to ArcGIS Server are members of group B which is member of group A.Using this configuration, users from domain B still cannot login to ArcGIS Server.Thanks,Matej
Hi,We have ArcGIS Server 10.2.1 now and it should support nested groups and domain forest since version 10.2.We have tried the configuration with nested groups, but did not succeed.What is the recommended configuration to allow logins to ArcGIS Server 10.2.1 from multiple domains?Thanks,Matej
I don't think it works as nested. I tried to add domain local group into Administrator role type, it didn't work. It didn't populate Role Members if you add a domain local group. but it works if it is global group. (all in Windows)
Hi Tony,Unfortunately ArcGIS Server does not seem to support a forest with multiple domains (unless there is a workaround that I am not aware).I suggest you have a talk with the System Administrator to create a nested group and load all domains to that group. You will require an account of a member that can see them all. That account is then used in ArcGIS Server Manager for accessing the nested group. Regards,Jose
Done.Could solve it at the DB level but have done it creating a superstructure hosting all the users and groups from multiple domains.Regards,Jose
Signed in members can post, follow updates, and more. New here? Register a free account.
Find useful guides, FAQs, and documents to help you navigate and make the most of Esri Community.