Link to home
Start Free TrialLog in
Avatar of Jay Thomas
Jay ThomasFlag for United Kingdom of Great Britain and Northern Ireland

asked on

AD LDS integrated with ADDS question

I'm confused about something and cannot find an answer on the net.
I have a ADDS infrastructure. A new application HAS to be deployed that requires schema changes.
I do not want to make schema changes so I deploy a AD LDS instance and add the application to the same server (not ideal but please bare with me).
My question - The application is accessed over the internal network by users already authenticated using Kerberos, The application requires users to be authenticated. How does AD LDS achieve this? Is it A, User objects get created in AD LDS instance along with the passwords. Or B, users objects are linked to ADDS some how and authorisation is passed to ADDS.

Anyone know how this works?
Thanks
Avatar of Shaun Vermaak
Shaun Vermaak
Flag of Australia image

It is A and you are probably going to have to do the schema extension for the application
Avatar of Jay Thomas

ASKER

Thanks for responding.

Could I do either of this, populate AD LDS user object with proxy object, the SID of ADDS user, would that cause ADLDS to go to ADDS to get authenticated, or perhaps ave some other tool such as FIM, synch the ADDS user objects from ADDS to ADLDS?
ASKER CERTIFIED SOLUTION
Avatar of Shaun Vermaak
Shaun Vermaak
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Many thanks