Installation manual

Using Microsoft Active Directory 107
Figure 8-4. Setting up Server Administrator Active Directory Objects in Multiple
Domains
To set up the objects for this multiple domain scenario, perform the
following tasks:
1
Ensure that the domain forest function is in Native mode.
2
Create two Association Objects, AO1 and AO2, in any domain. The figure
shows the objects in Domain1.
3
Create two Server Administrator Products, sys1 and sys2, to represent the
two systems. sys1 is in Domain1 and sys2 is in Domain2.
4
Create two Privilege Objects, Priv1 and Priv2, in which Priv1 has all
privileges (Administrator) and Priv2 has Login privileges.
5
Group sys2 into Group1. The group scope of Group1 must be
Universal
.
AO1 AO2
Priv2Priv1Group1
Group1sys1User3User2User1 sys2
Domain 1 Domain 2