# Multi Domain Administration

**URL:** <https://forums.suse.com/t/multi-domain-administration/15844>\
**Category:** SUSE Rancher Prime\
**Created:** [November 17, 2019, 10:18am UTC](https://forums.suse.com/t/multi-domain-administration/15844 "2019-11-17T10:18:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![akarancher](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@akarancher](https://forums.suse.com/u/akarancher)\
**Post date:** [November 17, 2019, 10:18am UTC](https://forums.suse.com/t/multi-domain-administration/15844/1 "2019-11-17T10:18:38Z")

</div>

Hi,

Please consider the following scenario for Active Directory Authentication with Rancher.  
We plan to deploy AD Domains, 1 per each app we are deploying - this is for regulatory purposes.  
-master.local = management domain for rancher admin cluster  
-app1.local = K8S application domain 1  
-app2.local = K8S application domain 2

Can rancher management cluster within master.local be configured to authenticate administration in both the application domains ? My aim is to only have a 1-way AD trust which allows management domain to be trusted by both App domains.

Thanks!

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [November 25, 2019, 7:46pm UTC](https://forums.suse.com/t/multi-domain-administration/15844/2 "2019-11-25T19:46:09Z")

</div>

You can only configure one AD server and one subtree of that server to search. So if those are all in the same server, then you could set the search base to the root and find users from the entire tree, then give individual users/groups from different domains roles on the various resources.
