In a multiple-domain environment, Meridian security is a little more complicated than in a single-domain environment, as shown in the following figure.
A user in Domain A can access the Meridian application server in Domain B and open a vault as long as there is full trust between the two domains. But if there are Meridian security roles assigned to the folder in the vault that the user attempts to access, Meridian needs to be able to query the domain of the user to determine the user’s group memberships. In order to be able to do that, the account in Domain B under which the AutoManager EDM Server service is running needs read access to the Member Of attribute of the user in Domain A.
To grant the service read access to the Member Of attribute: