Forum Discussion

Maurice_G_'s avatar
Maurice_G_
Icon for Employee rankEmployee
Sep 14, 2010

AD Query after logon to select domain for AD Auth

I am trying to figure out how to use the username provided on the Logon page to select the appropriate domain to AD Auth against. What I have done so far that fails is to use a branch rule per domain in my forest. Each branch rule performs an AD Query against a particular domain to determne if user is in a certain group...then forwards to AD Auth for that domain. My branch rules appear to do nothing however. Any ideas as to why this might be. In the logs I see the branch rules ENTER then LEAVE with no other logging information.

1 Reply

  • OK

    I got it worked out.

     

    See my policy below

     

    Access Policy: DDINet-Win7 (Endings: Allow, Deny [default])

     

     

    Start fallback Successful fallback Succeed

     

    Fail

     

    fallback

     

     

     

     

     

     

     

     

     

     

     

     

     

     

     

     

     

    Macro: AD-AUTH-ASIA (Terminals: Succeed [default], Fail) Use Count: 2

     

     

     

    Macro: AD-AUTH-AU (Terminals: Succeed [default], Fail) Use Count: 2

     

     

     

    Macro: AD-AUTH-UK (Terminals: Succeed [default], Fail) Use Count: 2

     

     

     

    Macro: AD-AUTH-US (Terminals: Succeed [default], Fail) Use Count: 2

     

     

     

    Macro: LDAP Query UPN (Terminals: Succeed [default], Fail) Use Count: 1

     

     

    In fallback WIN7-US Succeed Out

     

    Fail

     

    WIN7-UK Succeed Out

     

    Fail

     

    WIN7-ASIA Succeed Out

     

    Fail

     

    WIN7-AU Succeed Out

     

    Fail

     

    fallback WIN7-US Succeed Out

     

    Fail

     

    WIN7-UK Succeed Out

     

    Fail

     

    WIN7-ASIA Succeed Out

     

    Fail

     

    WIN7-AU Succeed Out

     

    Fail

     

    fallback

     

     

     

    Macro: US-Assign-Resources (Terminals: Out [default])