Alternative SSO

0

Hi

Have you guys used alternative SSO domain? For me primary SSO domain works ok. If I add second SSO domain as alternative, I get authentication failed.

I'm doing pre-authentication for Exchange 2016. Exchange's Active Directory has full trust to alternative SSO domain.

br

-teemu

2 comments

Avatar
0
Mark Deegan

hello Teemu,

it is recommended to have a LDAP server locally connected to the LM for authentication. If you have an alternate domain it should be in the parent forest rather than a trust to a different forest located externally. 

regards

Mark

Avatar
0
teemu.kirjavainen

Ok,

In this case I'm not able to change domain configuration. For primary authentication, I can use directly specific domain's DC or through trust to authenticate user. Alternate SSO authentication doesn't work either way.