Fragensteller
Exchange and Skype Server (on prem) in different Domains possible?

Frage
-
Hello,
i have the following situation.
We have all the infrastructure like Exchange server, citrix and all the users in a domain (domain A) which is part of a domain forrest (lets call it forest a) we are not allowed to do schema updates (which are needed for skype for business) with. therefore we created a second domain (B) (not part of forrest A), deployed the skype for business infrastructure (and did the needed schema updates).
we set the dns entries in the dns of domain a for sfb in domain b. its running and usable with own users in domain b.
now we need to connect the two domains, so we are able to do sso from domain A and (most important) connect the exchange server to the skykpe for business server. we are only able to do a unidirectional trust, as we are not domainowner of domain a. is there a chance to get this solved?
regards
- Bearbeitet Tidle Mittwoch, 25. November 2020 16:10
Alle Antworten
-
Moin,
SSO ist definitiv möglich, aber mit Hindernissen (man braucht Schatten-User im Skype Ressource Forest, und in diese Schattenuser muss man Vorname, Nachname und SID aus dem User Forest hineinsynchronisieren).
Exchange-Kopplung... die geht eigentlich über OAuth und Zertifikate, ich kann es mir also durchaus vorstellen. Gemacht oder gesehen habe ich es noch nicht.
Evgenij Smirnov
-
Automatisch wodurch? Ein Trust führt höchstens zur Erstellung von "Foreign Security Principals", aber Skype braucht ja echte User, an die es die Konfiguration hängen kann...
Evgenij Smirnov