Hi,
we rolled out Identity Awareness in an environment with a main domain and two subdomains with the Identity Collector. According the Admin Guide I defined additional LDAP Account Units for the subdomains, and the users of the subdomains get the roles of Access Roles defined for user groups of the LDAP Account Unit of the according subdomain. So far so good. But Access Roles defined for user groups of the LDAP Account Unit of the main domain are not assigned.
The LDAP Account Unit of the main domain is also used for VPN Users, and if the same user login via Remote Access VPN the Identity with roles of the subdomain and the main domain are propagated. The LDAP Account Unit of the main domain uses the GC, so for VPN users it works as expected.
Is it the intended behaviour, that identities propagated by domain logins get only roles for user groups of the subdomain?
And if so, is there any other workaround than to define AD user groups for users of the subdomain in the subdomain, and don't use subdomain users in user groups of the main domain? (I'm not the admin of the AD, I only use it)
The environment is still on R80.10, the update to R80.40 is already planned.
Regards,
Claudia