To import users and groups from multiple AD domains or multiple AD forests, you will need to register a domain controller or domain on the Umbrella dashboard for each AD domain that needs to be integrated with Umbrella. A separate connector deployment for each AD domain is recommended.
If you wish to use the same connector to provision user and group identities from multiple AD domains, ensure that the connector account is created with the same sAMAccountName and same password across all the domains. This feature is not enabled by default, and you will need to raise a support ticket to get this enabled. Using a single connector for multiple AD domains is mandatory if you have groups in an AD domain that have member users in another AD domain.
Updated 6 months ago