Pass-thru Authentication Security Issue

Jay Paff

Active Member
I need the advise from folks who understand Windows Domain security, group policies and pass-thru authentication via Citrix and Unified Logon services.

Essential this is the issue....
My division for my company is being sold to another company. We have JDE users at one of our mills that are going to stay with my current company. These users are in their own GPO and that GPO has been migrated from our division domain to the parent company's domain. Where the problem comes in is that we have the Citrix servers setup for pass-thru authentication to the JDE sign-on, i.e. the users fire-up their JDE Citrix icon, provide their domain credentials and that's it, they never get the JDE sign-on screen because pass-thru and unified logons have been configured. Most of these users don't even know their JDE sign-on credentials.

Once the GPO for these users were moved to the parent company's domain, the pass-thru and unified logon stopped working for them. Our work around has been to disable pass-thru so they get the JDE sign-on screen.

What suggestions do folks have for re-implementing pass-thru authentication for these folks? Eventually, they will put up their own JDE solution, they just don't have it now.

I am not real good with Windows domain security, but I do understand it somewhat.

Thanks in advance, Jay
 
If there is a trust between the domain where your Citrix and UnifiedLogon servers exist, and the domain where the users exist, it should not be a problem. Simply go into the UnifiedLogon configuration utility and add the new parent company Domain Users group or other such group where it is appropriate, while UnifiedLogon is shutdown of course, and fire it back up.

Unified Logon doesn't know anything about GPO - it knows users and groups, domain or local.
 
Back
Top