Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Updates & Insights
  • Questions
  • Learning
    • E-learning Courses
    • Empower Replay: Limited Edition
    • Tutorials
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • YouTube Videos
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Agility
      • Book your Agile Fundamentals training
      • Book you Kanban workshop
      • Learn more about Agile
        • Agile Webspace
        • Everything Agile
          • The Agile Manifesto
          • Best Practices
          • Retro Recipes
        • Methodologies
          • The Scrum Framework
          • Kanban
          • Extreme Programming
        • Roles
          • The Product Owner
          • The Agile Coach
          • The Quality & UX Coach (QX)
    • >> Go to DataMiner Docs
  • DevOps
    • About the DevOps Program
    • Sign up for the DevOps Pogram
    • DataMiner DevOps Support
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
  • Downloads
  • Contact
    • Sales, Training & Certification
    • DataMiner Support
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Solutions
    • Deal Registration
  • >> Go to dataminer.services

Setting up Dataminer for Multiple Active Directories in same Forest

Solved1.98K views13th October 2022Active Directory LDAP
3
Ryan Reuss [SLC] [DevOps Member]490 18th February 2022 0 Comments

Hello Team,

When adding multiple Active Directories into the System Center > System Settings > LDAP , the DataMiner help mentions:

  • In case DataMiner is required to directly access multiple domain controllers, you will need to change your DataMiner System configuration via System Center > System settings > LDAP, and provide the system with the correct LDAP (AD) information for each LDAP (AD) connection.

More detailed info on this can also be found in the DataMiner help pages available on any DataMiner Agent under the    section Advanced security configuration > Configuring LDAP settings.

https://docs.dataminer.services/user-guide/Advanced_Functionality/Security/Advanced_security_configuration/Configuring_LDAP_settings.html

I was wondering if there was an example for how this should look for the following: three separate domains in the same forest (we’ll call them XXX, YYY and ZZZ).

I just tested LDAP with a group as they are in the YYY domain.

I added the security group as a local group with the domain attached. Added admin permissions and access to all views. Tested logging in with two separate users that were both part of the security group and neither could log in.

I tested removing the ZZZ portion from the naming context just for fun, currently set as DC='111',DC='222', and it took about 15 minutes to pull up a list of security groups.

When adding an existing group is selected no groups pop up so I am assuming the current configuration is not working.

Thanks in advance!

André Kaiser [DevOps Advocate] Answered question 13th October 2022

3 Answers

  • Active
  • Voted
  • Newest
  • Oldest
0
André Kaiser [DevOps Advocate]532 Posted 13th October 2022 2 Comments

Dear Dojo community,
we have a setup of two domains with individual forests. There is a trust relationship between the two forests. We are able to connect DataMiner to both domains individually and import users and groups as required. The target is to use only a connection to domain B and be able to import and authenticate users and groups from domain A.

In domain B there are nested groups configured, that include groups and users from both forests.

  • When we import a nested group from domain B, that includes users from domain B only we see all of them in the users in DataMiner.
  • When we import a nested group from domain B, that includes users from domain B and users from domain A we see only the users of domain B in the users in DataMiner. Users from domain A are not resolved and thus cannot login to the DMS.

On the DMA on Windows Server level both groups and the users included are available and can be used for logon  and permission management. Here we also see, that domain B users are of type "User" and domain A users are of type "ForeignSecurityPrincipal" with a UID (-> referrals to domain A). DataMiner seem to behave differently. Does DataMiner recognize "ForeignSecurityPrincipals" as users and resolve them via referrals by default?
We already played around with the "referral=true/false" and different LDAP queries, that include foreign security principals as well, and tested the configuration as per the last comment in this thread, but did never reach state, where users from domain A became available through domain B.
Can you help with this or at least clarify if such a target shoudl be possible to reach with DM?

André Kaiser [DevOps Advocate] Posted new comment 15th November 2022
Wouter Bogaert [SLC] [DevOps Advocate] commented 15th November 2022

Hi André,
Just wanted to note that the original question and answers are about multiple domains in the same forest.
Looks like you are talking about 2 different forests.
I’m not sure if this is supported.

André Kaiser [DevOps Advocate] commented 15th November 2022

Hi Wouter.
Many thanks for your furtehr feedback. We have implemented a workaroudn now, where AD ressources are defined in domain A and AD roles with the user accounts in domain B. We imported the AD roles as DataMiner user groups now. This provides the intended funcionality.

You are viewing 1 out of 3 answers, click here to view all answers.
Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs

[ Placeholder content for popup link ] WordPress Download Manager - Best Download Management Plugin