Skip to Content

SSO for SAP BusinessObjects (Vintela) in a single forest multi domain environment

Hi Experts,

before asking this question I have to add, I have already experience with that Launchpad / Vintela / WinAD SSO thingy.

Now I got a new challenge. My customer has one AD forest with some domains (trusting each other). There is a forest root domain, let's call it CUSTOMER.CORP and some other domains on the same level such as CUSTOMER.DE, CUSTOMER.FR, CUSTOMER.CH etc. part of the same forest but with non-contiguous namespaces.

I wasn't able to figure out after doing some research in the SAP KBs two things:

a) where to create the required AD Service Account?

b) must the BO server (Windows) be a member of the CUSTOMER.CORP or not?

My assumption for a) is to create the Service Accounts and SPNs in the forest root domain CUSTOMER.CORP.

The BO server is already there and joined in the CUSTOMER.CH domain. We will start with that setup and I let you know how it will end ;) If there is someone out there who knows the answers, I would love to learn that.

Thanks and Regards,


Add a comment
10|10000 characters needed characters exceeded

Related questions

1 Answer

  • Posted on Feb 19, 2019 at 08:33 PM

    The KBA has the rules, technically the account can be in any of the trusted domains if you are using 2 way forest trusts. If not using two way forest trusts some combinations will not be possible via Microsoft trust rules, and others will be limited. This is for SSO for manual auth the krb5 will decide and the capaths could be a little difficult but should be linked in the above KBA as well


    Add a comment
    10|10000 characters needed characters exceeded

Before answering

You should only submit an answer when you are proposing a solution to the poster's problem. If you want the poster to clarify the question or provide more information, please leave a comment instead, requesting additional details. When answering, please include specifics, such as step-by-step instructions, context for the solution, and links to useful resources. Also, please make sure that you answer complies with our Rules of Engagement.
You must be Logged in to submit an answer.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MB each and 10.5 MB total.