Support for Foreign Groups

EFT Server allows you to specify only one domain and one group. However, that group can contain groups and users from foreign domains, as long as a trust relationship exists between the domains. This allows users from remote domains to authenticate to EFT Server. So, as long as a trust relationship exists between the domains, EFT Server can authenticate users from remote domains. The domain in which EFT Server resides will need to have a group that contains the foreign domain users.

The main point is that EFT Server simply talks to one AD/forest/controller. If that AD/forest/controller is properly configured to get information from the other domain/forest, then EFT Server will authenticate those users. This also applies to the Secure Ad Hoc Transfer (SAT) authentication module when AD authentication is used.

icon_info.gif

When your forest contains domain trees with many child domains and you observe noticeable user authentication delays between the child domains, you can optimize the user authentication process between the child domains by creating shortcut trusts to mid-level domains in the domain tree hierarchy. For more information, refer to When to create a shortcut trust on Microsoft's Web site. For details of controlling access to shared resources across domains, refer to the Microsoft TechNet article, Accessing resources across domains.

In the Windows Authentication page of the Site Setup wizard, you can specify any combination Domain and Group names, as long as the EFT Server service is running under an account that has rights to list users in that Domain and/or Group.

wiz_sitesetup_adauth64.gif

Login Requirements for Active Directory and Windows Local Account Permissions

illust_eft-adnetwork.gif