We have multiple Active Directory domains due to company mergers and acquisitions. We have synchronised those domains to Spotfire successfully and generally the application works well - users can access Spotfire, we're able to synchronise group membership and use those groups within Spotfire.
The problem comes when we have a group that has members from one of the other trusted domains. Spotfire will not sync those users into the members of the group, even though both domains are synched to Spotfire. AD handles this by having special 'Foreign security principal' objects in the domain where the group resides and these objects point to the actual users in a trusted domain. Ideally, Spotfire would follow these links and add users from other domains into groups.
Have just seen this after posting a duplicate idea - yes, strongly support this (for multiple-forest setups where global catalog approach won't work). This would significantly reduce admin burden and time taken for issue resolution.
Thanks Christian. We have three forests, one of which has multiple domains - so I guess my terminology wasn't terribly accurate - the problem we need to solve is the same one as you, membership that crosses forests.
Hi Pete we also want this functionality so you beat me to it. However are you aware that Spotfire does currently support Foreign security principals (FSPs) when using the LDAP Global Calalog, all the different domains are part of the same forests and all the groups are set to "Domain Local Scope" (which is a requirement for FSPs)? Unfortunately for us our corporate domains are on different forests so using the LDAP Global Calalog wouldn't work for us. Are your company's domains on different forests? If so this Idea makes sense. The Global Catalog LDAP service listens by default on port number 3268 (LDAP) or 3269 (LDAPS). Not all DCs have the Global Catalog, see below on how to "Determine Whether a Domain Controller Is a Global Catalog Server":
https://technet.microsoft.com/en-us/library/cc794880%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396