|
|
|
BlueCielo TeamWork 2012 Administrator's Guide | BlueCielo ECM Solutions |
In a multiple-domain environment, TeamWork security is a little more complicated than in a single-domain environment, as shown in the following figure.
A user in Domain A can access the TeamWork application server in Domain B and open a vault as long as there is full trust between the two domains. But if there are TeamWork security roles assigned to the folder in the vault that the user attempts to access, TeamWork needs to be able to query the domain of the user to determine the user’s group memberships. In order to be able to do that, the account in Domain B under which the AutoManager EDM Server service is running needs read access to the Member Of attribute of the user in Domain A.
To grant the service read access to the Member Of attribute:
Related concepts
About TeamWork support for Microsoft Active Directory
Understanding Active Directory security problems
Using TeamWork with nested groups
Using TeamWork with multiple domains
Related tasks
Granting domain privileges with a service account
Granting domain privileges to the TeamWork server
Copyright © 2000-2012 BlueCielo ECM Solutions |