User guide

server is set up to use Kerberos. When using Kerberos, the browse account cannot be
specified in the Full Pre-Windows 2000 Username form (domain\username). If the
username is in a sub-domain of the Active Directory domain (specified in step 3a),
then the username should be specified as <username>@<subdomain>.
b. Type the password for an Active Directory account that has browse rights in the
Password field.
c. Click Next.
9. The Establish Connection with Authentication Service window will open briefly. If the
external authentication service is added successfully, the Completed Successful window
will open.
10. Click Finish. The User Authentication Services window will open with the new service
listed.
NOTE: If the authentication service has trusted forests, the settings configured for the authentication service in the
Add Authentication Service Wizard will be applied to the discovered trusted forests. However, the settings for each
trusted forest can later be changed in the Authentication Service Connection Settings window.
See User Authentication Services Window on page 112 for more information about trusted
forests.
To change settings for the Active Directory external authentication service:
1. Click the Users tab.
2. Click Authentication in the top navigation bar. The User Authentication Services window
will open.
3. Click the name of the Active Directory (AD) service. The side navigation bar will change
to include the name of the AD service at the top and, below the name, the information you
may define.
4. Click Connection in the side navigation bar. The Authentication Service Connection
Settings - AD window will open.
5. Type a name in the Service Name field to change the name of the service that appears in
the Name column of the User Authentication Services window.
6. Type the domain name of the Active Directory service in the AD Domain Name field.
7. In the User Container field, specify the name of the container to search for user accounts.
This will limit the search scope to that container. The name may be entered in several
forms, optionally including a sub-domain. See To add an Active Directory external
authentication service: on page 90 for an explanation of the valid forms.
Chapter 6: Authentication Services 93