
Access Control
Sample Multi-Domain Setup
268
Sample Multi-Domain Setup
Rules for Local Domains
• One locally managed domain must be the base domain.
Note: If you configured the LDAP service immediately after enabling Access
Control on the Application Server, you must now restart iControl (see "Starting &
Stopping iControl Services", on page 552).
An operator from a parent domain (e.g. myCompany.com) can log
on to an application (e.g. iC Web) opened from this server, but
will have the permissions associated with role “operator” on
10.3.4.31. An operator from a sibling domain
(e.g. toronto.myCompany.com) will be denied access.
Comments to this Manuals