When a user does not provide a domain name e.g "domain\username" when logging in, then Spotfire will use all domains specified in the configuration to try and authenticate the user. The current behaviour of Spotfire is to search the domains in the order they appear in the configuration.xml under the "". Currently the administrator has to manually rearrange the entries in the configuration.xml file and set the order of the items to the order that they want the authentication to be performed in. It seems that the easiest would be to let the TSS administrator rearrange the LDAP entries in the Spotfire Configuration Tool UI and make sure that the order seen in Spotfire Configuration Tool UI is reflected in the configuration file.
We stopped using the Configuration Tool since it was too buggy and it was always messing the order of things in the XML file. So if you want to have real control use configuration.xml directly.