Please help me navigate credential inheritance across multiple domains.

Please help me navigate credential inheritance across multiple domains.

avatar

I'm in an environment with 4 main AD domains and I'm trying to set up synchronizers for each of them as we have thousands of servers so I need to automate populating my connections.

My goal is to have a set of credentials populated for each domain in each domain folder and then have all entried under that domain use those same credentials. I thought it was as simple as setting the Username, Domain and Passwd manually while editing the domain folder (i.e. one level down from the root data source) and then setting the synchronizer to "inherited" but no matter what I try, attempting a connection throws up an RDP login prompt with the domain pre-filled with my actual Windows login domain, not the domain of the server I'm trying to access.

I've tried several combinations of settings but nothing seems to work. I've read documentation and asked various AI LLMs to no avail. Manually setting inheritance for each server is a complete non-starter as there are too many to go through manually. It'd take me weeks and by the time it was done, my passwords would have expired and I'd have to do it all over again. I can't set credentials globally because it wouldn't work across the 4 AD domains (the DOMAIN\ prefix would be mismatched on all but whatever one I set).

I'm sure it's something simple I'm missing but I'm at my wits' end, so any assistance would be greatly appreciated.

All Comments (1)

avatar

Hello,

It should be as simple as leveraging templates and using one on your synchronizer. Templates are used to provide a base when creating entries, and can also be used through features like quick connect. You can create templates by going in RDM's ribbon at the top in the "administration tab", the "entry templates" button. You can read more about templates here: https://docs.devolutions.net/rdm/concepts/intermediate-concepts/templates/

In your case, you would need to create an RDP template with its credentials set to "inherited", and set that template in your synchronizer's template field.

Let me know if you need more information for how to set it up or if you encounter any issues doing so.

Regards,

Hubert Mireault

Ends in 10 days