Owner's Manual

150 Using the CMC With Microsoft Active Directory
Domain1, and user2 and user 3 are in Domain2. In this scenario, configure
user1 and user 2 with administrator privileges to both CMCs and configure
user3 with login privileges to the RAC2 card.
Figure 6-3. Setting Up Active Directory Objects in Multiple Domains
To configure the objects for the multiple domain scenario:
1
Ensure that the domain forest function is in Native or Windows 2003
mode.
2
Create two Association Objects, A01 (of Universal scope) and A02, in any
domain.
Figure 6-3 shows the objects in Domain2.
3
Create two RAC Device Objects, RAC1 and RAC2, to represent the two
CMCs.
4
Create two Privilege Objects, Priv1 and Priv2, in which Priv1 has all
privileges (administrator) and Priv2 has login privilege.
5
Group user1 and user2 into Group1. The group scope of Group1 must be
Universal.
AO1 AO2
Priv2Priv1Group1
RAC2RAC1User3User2User1
Domain2Domain1