How Cells Are Processed in AD Bridge

When an Active Directory user logs on to an AD Bridge Enterprise client computer, the AD Bridge Enterprise agent searches Active Directory for the user's AD Bridge cell information.

The search typically begins at the node where the computer is joined to Active Directory and can extend to all forests that have a two-way transitive trust with the client computer's forest.

The AD Bridge Enterprise agent determines the OU where the computer is a member and checks whether a named cell is associated with it.

If a cell is not associated with the OU, the AD Bridge Enterprise agent on the Unix or Linux computer moves up the directory structure, searching the parent and grandparent OUs until it finds an OU that has an AD Bridge cell associated with it.

If a named cell is found, AD Bridge Enterprise searches for a user or group's attributes in the cell associated with the computer.

If an OU with an associated cell is not found, the AD Bridge Enterprise agent uses the default cell for the domain to map the username to UID and GID information.

Default Cell Processing

A default cell is processed differently than a named cell. When processing a default cell, AD Bridge Enterprise searches for a user or group's attributes in the default cell of the domain where the user or group resides. For example, a two-domain topology configured with one domain for users and another domain for computers would require two default cells:

  • a default cell in the domain where user and group objects reside
  • a default cell in the domain where computer objects are joined

A Linux or Unix computer can be a member of an OU that does not have a cell associated with it. In such a case, the Group Policy Objects (GPOs) associated with the OU apply to the Linux or Unix computer, but user UID and GID mappings follow the policy of the nearest parent cell or the default cell.

AD Bridge Enterprise does not require you to have a default cell, but for AD Bridge Enterprise to operate properly you must ensure that the AD Bridge Enterprise agent can always find a cell.

For more information about modes, cells, and user rights, please see the AD Bridge Best Practices Guide.