Users Guide

Using Microsoft Active Directory 153
Figure 10-3 shows how to setup the Active Directory objects in multiple
domains for RAC. In this scenario, you have two DRAC 4 cards (RAC1 and
RAC2) and three existing Active Directory users (User1, User2, and User3).
User1 is in Domain1, but User2 and User3 are in Domain2. You want to give
User1 and User2 Administrator privileges on both the RAC1 and the RAC2
card and give User3 a Login privilege on the RAC2 card.
Figure 10-3. Setting Up RAC Active Directory Objects in Multiple Domains
To set up the objects for this multiple domain scenario, perform the
following tasks:
1
Ensure that the domain forest function is in Native or Windows 2003
mode.
2
Create two Association Objects, AO1 (of Universal scope) and AO2, in any
domain. The figure shows the objects in Domain2.
3
Create two RAC Device Objects, RAC1 and RAC2, to represent the two
remote systems.
4
Create two Privilege Objects, Priv1 and Priv2, in which Priv1 has all
privileges (Administrator) and Priv2 has Login privileges.
AO1 AO2
Priv2Priv1Group1
RAC2RAC1User3User2User1
Domain2
Domain1