{"id":101962,"date":"2025-01-22T16:33:25","date_gmt":"2025-01-22T08:33:25","guid":{"rendered":"https:\/\/version-2.com\/?p=101962"},"modified":"2025-01-15T16:36:11","modified_gmt":"2025-01-15T08:36:11","slug":"cross-forest-authentication-with-thinfinity-secure-multi-domain-access","status":"publish","type":"post","link":"https:\/\/version-2.com\/zh\/2025\/01\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/","title":{"rendered":"Cross-forest authentication with Thinfinity: secure multi-domain access"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"101962\" class=\"elementor elementor-101962\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a9966c4 post-content elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a9966c4\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;437ef7f&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2884b38\" data-id=\"2884b38\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-980bf1e elementor-widget elementor-widget-text-editor\" data-id=\"980bf1e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-1.png\" width=\"1146\" height=\"802\" \/><\/p><div class=\"elementor-widget-container\"><div class=\"elementor elementor-9003241321013682\" data-elementor-type=\"wp-post\" data-elementor-id=\"9003241321013682\" data-elementor-post-type=\"post\"><div class=\"elementor-element elementor-element-8655df9 e-con-full thegem-e-con-layout-elementor e-flex e-con e-parent e-lazyloaded\" data-id=\"8655df9\" data-element_type=\"container\" data-settings=\"{&quot;thegem_container_layout&quot;:&quot;elementor&quot;}\"><div class=\"elementor-element elementor-element-eefa46c flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"eefa46c\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h2>Introduction\u00a0<\/h2><p>In modern enterprises, IT environments often span multiple <b>Active Directory (AD) forests<\/b>, hybrid cloud platforms, and external identity providers (IDPs) such as <b>Azure Entra ID, Okta, and PingID<\/b>. Securely managing authentication across these disparate environments is a critical challenge for <b>CIOs, CISOs, and IT administrators.<\/b><\/p><p>Thinfinity provides a powerful <b>Cross-Forest Authentication<\/b> solution through <b>Global Account Mapping<\/b>, ensuring seamless user authentication across multiple domains while maintaining a <b>Zero Trust Security Model<\/b>. This article explores how Thinfinity achieves secure cross-domain authentication, leveraging <b>2FA, external IDPs, and directory federation.<\/b><\/p><div>\u00a0<\/div><\/div><\/div><\/div><div class=\"elementor-element elementor-element-a46640b e-transform flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-menu-anchor\" data-id=\"a46640b\" data-element_type=\"widget\" data-settings=\"{&quot;_transform_translateX_effect&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:0,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:-150,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_widescreen&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_widescreen&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"menu-anchor.default\"><div class=\"elementor-widget-container\"><div id=\"What_is_Cross-Forest_Authentication\" class=\"elementor-menu-anchor\">\u00a0<\/div><\/div><\/div><div class=\"elementor-element elementor-element-3d03e22 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"3d03e22\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h2>What is cross-forest authentication?<\/h2><h3>Defining active directory (AD) forests<\/h3><p>An <b>Active Directory forest<\/b> is the highest-level security boundary in a<b> Windows Server <\/b>environment. Multiple forests can exist within an organization due to:<\/p><ul><li><b>Mergers &amp; Acquisitions:<\/b> Different companies with separate AD infrastructures.<\/li><li><b>Security Segmentation:<\/b> Isolating user groups or business units.<\/li><li><b>Geographic Distribution: <\/b>Multiple regional offices managing separate IT infrastructures.<\/li><\/ul><\/div><\/div><\/div><div class=\"elementor-element elementor-element-f4c7780 e-transform flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-menu-anchor\" data-id=\"f4c7780\" data-element_type=\"widget\" data-settings=\"{&quot;_transform_translateX_effect&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:0,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:-150,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_widescreen&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_widescreen&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"menu-anchor.default\"><div class=\"elementor-widget-container\"><div id=\"Challenges_in_Cross-Forest_Authentication\" class=\"elementor-menu-anchor\">\u00a0<\/div><\/div><\/div><div class=\"elementor-element elementor-element-92ccf0a flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"92ccf0a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h3>Challenges in cross-forest authentication<\/h3><p>Cross-forest authentication becomes a challenge when users need to access resources <b>outside their native AD forest<\/b>. The main obstacles include:<\/p><ol><li><b>Credential Duplication:<\/b> Users often require separate accounts for each domain.<\/li><li><b>Lack of SSO (Single Sign-On):<\/b> Logging into multiple domains requires multiple authentications.<\/li><li><b>Security Risks:<\/b> Traditional authentication mechanisms expose organizations to <b>credential theft and privilege escalation<\/b> attacks.<\/li><li><b>Limited Integration with Modern IDPs:<\/b> Many enterprises are moving to <b>Azure Entra ID, Okta, and other cloud IDPs<\/b> but still require legacy <b>on-premises AD integration.<\/b><\/li><\/ol><\/div><\/div><\/div><div class=\"elementor-element elementor-element-5fb5148 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"5fb5148\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h2>Cross-Forest Authentication Challenges<\/h2><\/div><\/div><\/div><div class=\"elementor-element elementor-element-b752387 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-image\" data-id=\"b752387\" data-element_type=\"widget\" data-widget_type=\"image.default\"><div class=\"elementor-widget-container\"><img decoding=\"async\" class=\"attachment-large size-large wp-image-9003241321013773\" src=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-challenges-1.png\" sizes=\"(max-width: 1007px) 100vw, 1007px\" srcset=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-challenges-1.png 1007w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-challenges-1-768x302.png 768w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-challenges-1-600x236.png 600w\" alt=\"Cross-forest authentication challenges: credential duplication, lack of SSO, security risks, and limited IDP integration (Azure Entra ID, Okta)\" width=\"1007\" height=\"396\" \/><\/div><\/div><div class=\"elementor-element elementor-element-6c59a49 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"6c59a49\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h3>The need for a secure cross-forest solution<\/h3><p>To address these issues, organizations require:<\/p><ul><li><b>A unified authentication mechanism<\/b> that works across AD forests.<\/li><li><b>Seamless integration with cloud IDPs <\/b>like <b>Azure Entra ID, Okta, OneLogin, and ForgeRock.<\/b><\/li><li><b>Zero Trust Network Access (ZTNA)<\/b> principles that ensure users only access authorized resources.<\/li><\/ul><p>This is where <b>Thinfinity\u2019s Global Account Mapping<\/b> comes into play.<\/p><\/div><\/div><\/div><div class=\"elementor-element elementor-element-ecb15c0 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"ecb15c0\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h2>Thinfinity\u2019s global account mapping: How it works<\/h2><p>Thinfinity simplifies cross-forest authentication by implementing <b>Global Account Mapping<\/b>, which associates external user identities with <b>Thinfinity accounts and resource identities.<\/b><\/p><h3>Step-by-Step Process of Thinfinity\u2019s cross-forest authentication<\/h3><h4>1. External authentication via IDPs &amp; Federation services<\/h4><ul><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">Thinfinity supports authentication from <\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"><b>Google, Microsoft AD, Azure Entra ID, Okta, DUO, Auth0, ForgeRock, JumpCloud, PingID, and OneLogin.<\/b><\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">\u00a0<\/span><\/li><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">Supports <\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"><b>SAML and OAuth 2.0<\/b><\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"> for federated authentication.<\/span><\/li><li><span style=\"color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-align: var(--text-align); text-transform: var( --e-global-typography-text-text-transform );\">Thinfinity validates the user\u2019s identity against <\/span><span style=\"color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-align: var(--text-align); text-transform: var( --e-global-typography-text-text-transform );\"><b>their primary domain<\/b><\/span><span style=\"color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-align: var(--text-align); text-transform: var( --e-global-typography-text-text-transform );\">.<\/span><\/li><\/ul><h4>2. Global mapping of user identities<\/h4><ul><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">Thinfinity <strong>maps the authenticated user<\/strong> from an external domain to the <strong>internal AD forest account.<\/strong><\/span><\/li><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">This ensures that <strong>external and internal users are seamlessly linked<\/strong>.<\/span><\/li><\/ul><h4>3. Role-based access vontrol (RBAC) enforcement<\/h4><ul><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">After authentication, <strong>Thinfinity assigns roles<\/strong> based on <strong>Active Directory groups<\/strong> or <strong>Thinfinity IDP policies<\/strong>.<\/span><\/li><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">Access is granted only to resources authorized for the assigned role.<\/span><\/li><\/ul><h4>4. Authorization for specific resources<\/h4><ul><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">Thinfinity ensures that <\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">only mapped identities<\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"> can access <\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">Active Directory<\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">, <\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">Local Users<\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">, <\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">and Database-based User Apps (SQL, MongoDB, etc.)<\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">.<\/span><\/li><\/ul><h4>5. Seamless multi-domain access<\/h4><ul><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">Thinfinity supports authentication and resource <strong>access across Corporate Domains and Secondary Domains<\/strong>.<\/span><\/li><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">This eliminates the need for users to manage <strong>multiple passwords across different forests.<\/strong><\/span><\/li><\/ul><\/div><\/div><\/div><div class=\"elementor-element elementor-element-f07f7a9 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-image\" data-id=\"f07f7a9\" data-element_type=\"widget\" data-widget_type=\"image.default\"><div class=\"elementor-widget-container\"><img decoding=\"async\" class=\"attachment-large size-large wp-image-9003241321013763\" src=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/global-account-mapping-architecture.png\" sizes=\"(max-width: 1009px) 100vw, 1009px\" srcset=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/global-account-mapping-architecture.png 1009w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/global-account-mapping-architecture-768x425.png 768w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/global-account-mapping-architecture-672x372.png 672w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/global-account-mapping-architecture-600x332.png 600w\" alt=\"Thinfinity cross-forest authentication: SSO, MFA, RBAC, IDP integration (Azure Entra ID, Okta), secure multi-domain access, and role-based authorization\" width=\"1009\" height=\"559\" \/><\/div><\/div><div class=\"elementor-element elementor-element-89f6dd5 e-transform flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-menu-anchor\" data-id=\"89f6dd5\" data-element_type=\"widget\" data-settings=\"{&quot;_transform_translateX_effect&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:0,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:-150,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_widescreen&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_widescreen&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"menu-anchor.default\"><div class=\"elementor-widget-container\"><div id=\"Key_benefits\" class=\"elementor-menu-anchor\">\u00a0<\/div><\/div><\/div><div class=\"elementor-element elementor-element-daba241 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"daba241\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h2>Key benefits of Thinfinity\u2019s cross-forest authentication solution<\/h2><h3>1. Secure access without VPN dependencies<\/h3><p>Traditional <b>VPN-based solutions<\/b> struggle with cross-forest authentication, often requiring complex <b>trust relationships<\/b>. Thinfinity eliminates these issues by providing <b>direct browser-based authentication<\/b> using secure web protocols.<\/p><h3>2. Seamless integration with Cloud IDPs &amp; Multi-factor authentication (2FA)<\/h3><p>Thinfinity integrates with <b>leading identity providers<\/b> like:<\/p><ul><li>Azure Entra ID<\/li><li>Okta<\/li><li>PingID<\/li><li>OneLogin<\/li><li>Google Workspace<\/li><li>Duo Security<\/li><li>Auth0<\/li><li>ForgeRock<\/li><\/ul><p>This ensures that users can <b>leverage existing identity platforms<\/b> while securing authentication with <b>MFA (Multi-Factor Authentication)<\/b>.<\/p><h3>3. Unified identity management with active directory &amp; external domains<\/h3><p>Thinfinity creates a <b>centralized authentication layer<\/b>, mapping <b>external identities<\/b> to i<b>nternal AD resources<\/b>. This allows:<\/p><ul><li>Users to log in once and access resources <b>across multiple forests<\/b>.<\/li><li><b>RBAC (Role-Based Access Control)<\/b> enforcement to restrict unauthorized access.<\/li><li><b>Elimination of duplicate credentials<\/b> across different forests.<\/li><\/ul><h3>4. Support for hybrid and Multi-Cloud environments<\/h3><p>Many enterprises <b>run workloads across multiple clouds<\/b> and require <b>cross-domain authentication<\/b> for:<\/p><ul><li><b>On-premises<\/b> <b>Active Directory<\/b><\/li><li><b>Cloud-hosted Azure Entra ID<\/b><\/li><li><b>Hybrid cloud environments (AWS, GCP, Azure, private clouds)<\/b><\/li><\/ul><p>Thinfinity ensures authentication is <b>seamless across these environments<\/b>, enabling <b>secure access control.<\/b><\/p><h3>5. Zero Trust architecture (ZTA) compliance<\/h3><p>Thinfinity aligns with <b>Zero Trust principles<\/b>, ensuring:<\/p><ul><li><b>Least Privilege Access<\/b>: Users can only access authorized applications.<\/li><li><b>Adaptive Authentication<\/b>: Based on device, location, and risk analysis.<\/li><li><b>Continuous Monitoring: <\/b>Tracking authentication events and potential <b>anomalies<\/b>.<\/li><\/ul><div>\u00a0<\/div><\/div><\/div><\/div><div class=\"elementor-element elementor-element-985aee2 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-image\" data-id=\"985aee2\" data-element_type=\"widget\" data-widget_type=\"image.default\"><div class=\"elementor-widget-container\"><img loading=\"lazy\" decoding=\"async\" class=\"attachment-large size-large wp-image-9003241321013774\" src=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/thinfinity-cross-forest-1.png\" sizes=\"(max-width: 1008px) 100vw, 1008px\" srcset=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/thinfinity-cross-forest-1.png 1008w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/thinfinity-cross-forest-1-768x447.png 768w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/thinfinity-cross-forest-1-600x349.png 600w\" alt=\"Thinfinity cross-forest authentication: SSO, MFA, IDP integration (Azure Entra ID, Okta), hybrid cloud support, and Zero Trust compliance\" width=\"1008\" height=\"587\" \/><\/div><\/div><div class=\"elementor-element elementor-element-b18c7c1 e-transform flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-menu-anchor\" data-id=\"b18c7c1\" data-element_type=\"widget\" data-settings=\"{&quot;_transform_translateX_effect&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:0,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:-150,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_widescreen&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_widescreen&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"menu-anchor.default\"><div class=\"elementor-widget-container\"><div id=\"Use_cases\" class=\"elementor-menu-anchor\">\u00a0<\/div><\/div><\/div><div class=\"elementor-element elementor-element-0528981 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"0528981\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h2>Use Cases<\/h2><h3>Use case 1: Enterprise deployment of cross-forest authentication<\/h3><h4>Scenario: Multi-Domain Organization with External IDP<\/h4><h5>A global enterprise has:<\/h5><ul><li><b>Corporate AD Domain (HQ)<\/b><\/li><li><b>Regional Active Directory Domains (Europe, APAC, Americas)<\/b><\/li><li><b>Cloud-based Azure Entra ID for remote users<\/b><\/li><li><b>Okta authentication for contractors<\/b><\/li><\/ul><h5>Thinfinity\u2019s solution<\/h5><ol><li>Users log in <b>using Okta\/Azure Entra ID credentials.<\/b><\/li><li>Thinfinity <b>maps external users<\/b> to their corresponding <b>AD accounts<\/b> in the primary domain.<\/li><li>Users authenticate once and gain access to all <b>authorized applications<\/b>.<\/li><li><b>2FA is enforced<\/b> on each log in to enhance security.<\/li><li>Access is logged for <b>auditing and compliance.<\/b><\/li><\/ol><h5>Outcome<\/h5><p><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span>\u00a0Seamless authentication across multiple forests<\/p><p><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span> No password duplication or credential sprawl.<\/p><p><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span> Increased security via MFA and RBAC.<\/p><\/div><\/div><\/div><div class=\"elementor-element elementor-element-5118d3a flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"5118d3a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h2>Achieving Seamless Enterprise Authentication<\/h2><\/div><\/div><\/div><div class=\"elementor-element elementor-element-de3143a flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-image\" data-id=\"de3143a\" data-element_type=\"widget\" data-widget_type=\"image.default\"><div class=\"elementor-widget-container\"><img loading=\"lazy\" decoding=\"async\" class=\"attachment-large size-large wp-image-9003241321013775\" src=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/achieving-seamless-enterprise-authentication-1.png\" sizes=\"(max-width: 1008px) 100vw, 1008px\" srcset=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/achieving-seamless-enterprise-authentication-1.png 1008w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/achieving-seamless-enterprise-authentication-1-768x458.png 768w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/achieving-seamless-enterprise-authentication-1-600x358.png 600w\" alt=\"Enterprise cross-forest authentication: Thinfinity enables SSO, MFA, RBAC with Azure Entra ID, Okta, secure access, and audit logging.\" width=\"1008\" height=\"601\" \/><\/div><\/div><div class=\"elementor-element elementor-element-906ab1d flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"906ab1d\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h3>Use Case 2: MSP-Hosted applications with customer-managed authentication<\/h3><h4>Scenario: Multi-Tenant MSP with Customer-Managed IDPs<\/h4><p><b>A Managed Service Provider (MSP)<\/b> offers hosted applications to multiple customers. Each customer:<\/p><ul><li>Manages their own Azure Entra ID or Okta authentication.<\/li><li>Requires Single Sign-On (SSO) to access MSP-managed applications.<\/li><li>Has users in different Active Directory (AD) domains and requires seamless cross-forest authentication.<\/li><\/ul><h4>Challenges faced by the MSP<\/h4><h5>1. Multi-Tenant Identity Management<\/h5><ul><li>Customers do not want to provision separate credentials for the MSP\u2019s environment.<\/li><li>The MSP must support authentication via<strong> each customer\u2019s existing IDP (Azure Entra ID, Okta, etc.).<\/strong><\/li><\/ul><h5>2. Secure Access Without VPN or Direct AD Trusts<\/h5><ul><li>VPN tunnels or <strong>Active Directory trust relationships<\/strong> with the MSP.<\/li><li>Traditional cross-domain authentication methods increase complexity and security risks.<\/li><\/ul><h5>3. Single Sign-On (SSO) to Hosted Applications<\/h5><ul><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">Users should authenticate once <\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"><b>via their own Entra ID<\/b><\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"> or <\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"><b>Okta accounts<\/b><\/span><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">.<\/span><\/li><li><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); font-weight: var( --e-global-typography-text-font-weight ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\">They should get<strong> automatic access<\/strong> to applications hosted in the MSP\u2019s data center or cloud.<\/span><\/li><\/ul><h3>Thinfinity\u2019s solution: Global account mapping for MSPs<\/h3><p>Thinfinity enables secure<b> cross-forest authentication and SSO<\/b> between:<\/p><p><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span> <b>Customer-Managed Identity Providers (Azure Entra ID, Okta, PingID, etc.)<\/b><\/p><p><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span> <b>MSP-Hosted Applications<\/b><\/p><p>Using <b>Global Account Mapping<\/b>, Thinfinity:<\/p><ol><li><b>Authenticates users via their customer-managed IDP (Azure Entra ID, Okta, etc.)<\/b><\/li><li><b>Maps the authenticated identity to a corresponding Thinfinity account<\/b> in the MSP\u2019s domain.<\/li><li><b>Grants access to MSP-hosted applications via SSO<\/b>, enforcing Role-Based Access Control (RBAC).<\/li><\/ol><h3>How it works<\/h3><ol><li><b>User logs into Thinfinity using their existing IDP (Azure Entra ID or Okta).<\/b><\/li><li><b>Thinfinity validates authentication <\/b>via <b>SAML or OAuth 2.0.<\/b><\/li><li><b>Global Account Mapping links the external IDP user<\/b> to an internal account in the MSP\u2019s environment.<\/li><li><b>Thinfinity grants SSO access<\/b> to the MSP\u2019s hosted applications.<\/li><\/ol><h3>Outcome &amp; business impact<\/h3><p><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span><b> Customers authenticate using their existing credentials<\/b>\u2014no need to manage extra accounts.<\/p><p><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span>\u00a0<b>Seamless Single Sign-On (SSO)<\/b> to MSP-hosted applications.<\/p><p><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span>\u00a0<b>No VPNs or direct AD trust relationships required<\/b>, reducing security risks.<\/p><p><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span>\u00a0<b>Full Role-Based Access Control (RBAC)<\/b> ensures users access only authorized applications.<\/p><\/div><\/div><\/div><div class=\"elementor-element elementor-element-c028ddb flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"c028ddb\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h2>Thinfinity\u2019s Global Account Mapping Process<\/h2><\/div><\/div><\/div><div class=\"elementor-element elementor-element-d8bb3f4 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-image\" data-id=\"d8bb3f4\" data-element_type=\"widget\" data-widget_type=\"image.default\"><div class=\"elementor-widget-container\"><img loading=\"lazy\" decoding=\"async\" class=\"attachment-large size-large wp-image-9003241321013776\" src=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/global-account-mapping-process-1.png\" sizes=\"(max-width: 1008px) 100vw, 1008px\" srcset=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/global-account-mapping-process-1.png 1008w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/global-account-mapping-process-1-768x316.png 768w, https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/global-account-mapping-process-1-600x247.png 600w\" alt=\"MSP cross-forest authentication: Thinfinity enables SSO, MFA, RBAC with Azure Entra ID, Okta, secure access to MSP-hosted applications\" width=\"1008\" height=\"415\" \/><\/div><\/div><div class=\"elementor-element elementor-element-7dc7dd7 flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"7dc7dd7\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h3>Why Thinfinity is the ideal solution for MSPs<\/h3><ul><li><b>Multi-Tenant Ready:<\/b> Supports customer-managed authentication while centralizing access to hosted apps.<\/li><li><b>Cloud-First Security:<\/b> Enables<b> Zero Trust<\/b> authentication across multiple identity providers.<\/li><li><b>Seamless Cross-Forest Authentication:<\/b> Bridges customer <b>IDPs with MSP-hosted environments.<\/b><\/li><li><b>Looking to enable secure SSO for MSP-hosted applications? <\/b>Thinfinity\u2019s <b>Global Account Mapping<\/b> provides the <b>best solution for multi-tenant authentication.<\/b><\/li><\/ul><div>\u00a0<\/div><\/div><\/div><\/div><div class=\"elementor-element elementor-element-9569afa e-transform flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-menu-anchor\" data-id=\"9569afa\" data-element_type=\"widget\" data-settings=\"{&quot;_transform_translateX_effect&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:0,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:-150,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_widescreen&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateX_effect_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_widescreen&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;_transform_translateY_effect_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"menu-anchor.default\"><div class=\"elementor-widget-container\"><div id=\"Conclusion\" class=\"elementor-menu-anchor\">\u00a0<\/div><\/div><\/div><div class=\"elementor-element elementor-element-63934fd flex-horizontal-align-default flex-horizontal-align-tablet-default flex-horizontal-align-mobile-default flex-vertical-align-default flex-vertical-align-tablet-default flex-vertical-align-mobile-default elementor-widget elementor-widget-text-editor\" data-id=\"63934fd\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\"><div class=\"elementor-widget-container\"><div class=\"elementor-text-editor elementor-clearfix\"><h2>Conclusion<\/h2><p>Thinfinity\u2019s <b>Global Account Mapping for Cross-Forest Authentication<\/b> provides enterprises with a <b>secure, scalable, and seamless<\/b> solution for managing authentication across <b>Active Directory forests and external identity providers.<\/b><\/p><p>By integrating<b> Azure Entra ID, Okta, and other IDPs<\/b>, Thinfinity eliminates the <b>complexities of cross-domain authentication <\/b>while enforcing <b>Zero Trust security<\/b> and <b>Multi-Factor Authentication.<\/b><\/p><p>With <b>Thinfinity<\/b>, enterprises can <b>modernize their authentication strategy,<\/b> ensuring users can securely access resources <b>across all domains, clouds, and hybrid environments.<\/b><\/p><h3>Key takeaways:<\/h3><p><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"><b><span style=\"color: #0a74d6;\">\u2713<\/span> <\/b>Supports Cross-Forest Authentication without VPNs<\/span><\/p><p><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span> Seamless Integration with External IDPs (Azure Entra ID, Okta, DUO, etc.)<\/span><\/p><p><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span> Role-Based Access Control (RBAC) &amp; MFA for Security<\/span><\/p><p><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span> Zero Trust &amp; Secure Web Access Model<\/span><\/p><p><span style=\"text-align: var(--text-align); color: var( --e-global-color-twbb_black ); font-family: var( --e-global-typography-text-font-family ), sans-serif; font-size: var( --e-global-typography-text-font-size ); font-style: var( --e-global-typography-text-font-style ); letter-spacing: var( --e-global-typography-text-letter-spacing ); text-transform: var( --e-global-typography-text-text-transform );\"><span style=\"color: #0a74d6;\"><b>\u2713<\/b><\/span> Improves IT Efficiency by Eliminating Credential Duplication<\/span><\/p><div>\u00a0<\/div><\/div><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-241e357 elementor-widget elementor-widget-shortcode\" data-id=\"241e357\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\n\t\t<div data-elementor-type=\"page\" data-elementor-id=\"91826\" class=\"elementor elementor-91826\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4dcebe91 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"4dcebe91\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;58112d0&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-126baa3\" data-id=\"126baa3\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2bcedeed elementor-widget elementor-widget-text-editor\" data-id=\"2bcedeed\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>About Cybele Software Inc.<br \/><\/strong>We help organizations extend the life and value of their software. Whether they are looking to improve and empower remote work or turn their business-critical legacy apps into modern SaaS, our software enables customers to focus on what\u2019s most important: expanding and evolving their business.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\n\t\t<div data-elementor-type=\"page\" data-elementor-id=\"18103\" class=\"elementor elementor-18103\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-748947f elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"748947f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7995c19\" data-id=\"7995c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a437045 elementor-widget elementor-widget-image-box\" data-id=\"a437045\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">About Version 2 Digital<\/h3><p class=\"elementor-image-box-description\">Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.\n<br><br>\nThrough an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Introduction\u00a0 In modern enterprises, IT environments of [&hellip;]<\/p>\n","protected":false},"author":149011790,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1305,1297,61],"tags":[1077,1301],"class_list":["post-101962","post","type-post","status-publish","format-standard","hentry","category-1305","category-cybele","category-press-release","tag-1077","tag-cybele"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cross-forest authentication with Thinfinity: secure multi-domain access - Version 2<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/\" \/>\n<meta property=\"og:locale\" content=\"zh_HK\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cross-forest authentication with Thinfinity: secure multi-domain access - Version 2\" \/>\n<meta property=\"og:description\" content=\"Introduction\u00a0 In modern enterprises, IT environments of [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/\" \/>\n<meta property=\"og:site_name\" content=\"Version 2\" \/>\n<meta property=\"article:published_time\" content=\"2025-01-22T08:33:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-1.png\" \/>\n<meta name=\"author\" content=\"tracylamv2\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"tracylamv2\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9810\u8a08\u95b1\u8b80\u6642\u9593\" \/>\n\t<meta name=\"twitter:data2\" content=\"22 \u5206\u9418\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blog.cybelesoft.com\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2025\\\/01\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/\"},\"author\":{\"name\":\"tracylamv2\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/011bc7c3731c930bcfeecd52fefb6365\"},\"headline\":\"Cross-forest authentication with Thinfinity: secure multi-domain access\",\"datePublished\":\"2025-01-22T08:33:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2025\\\/01\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/\"},\"wordCount\":1318,\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.cybelesoft.com\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.cybelesoft.com\\\/wp-content\\\/uploads\\\/2025\\\/01\\\/cross-forest-auth-1.png\",\"keywords\":[\"2025\",\"Cybele\"],\"articleSection\":[\"2025\",\"Cybele\",\"Press Release\"],\"inLanguage\":\"zh-HK\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/version-2.com\\\/2025\\\/01\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/\",\"url\":\"https:\\\/\\\/blog.cybelesoft.com\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/\",\"name\":\"Cross-forest authentication with Thinfinity: secure multi-domain access - Version 2\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/blog.cybelesoft.com\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.cybelesoft.com\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.cybelesoft.com\\\/wp-content\\\/uploads\\\/2025\\\/01\\\/cross-forest-auth-1.png\",\"datePublished\":\"2025-01-22T08:33:25+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/blog.cybelesoft.com\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/#breadcrumb\"},\"inLanguage\":\"zh-HK\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/blog.cybelesoft.com\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/blog.cybelesoft.com\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/#primaryimage\",\"url\":\"https:\\\/\\\/blog.cybelesoft.com\\\/wp-content\\\/uploads\\\/2025\\\/01\\\/cross-forest-auth-1.png\",\"contentUrl\":\"https:\\\/\\\/blog.cybelesoft.com\\\/wp-content\\\/uploads\\\/2025\\\/01\\\/cross-forest-auth-1.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/blog.cybelesoft.com\\\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9801\",\"item\":\"https:\\\/\\\/version-2.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cross-forest authentication with Thinfinity: secure multi-domain access\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"name\":\"Version 2\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/version-2.com\\\/zh\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"zh-HK\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\",\"name\":\"Version 2\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"width\":1795,\"height\":335,\"caption\":\"Version 2\"},\"image\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/011bc7c3731c930bcfeecd52fefb6365\",\"name\":\"tracylamv2\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"caption\":\"tracylamv2\"},\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/author\\\/tracylamv2\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cross-forest authentication with Thinfinity: secure multi-domain access - Version 2","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/","og_locale":"zh_HK","og_type":"article","og_title":"Cross-forest authentication with Thinfinity: secure multi-domain access - Version 2","og_description":"Introduction\u00a0 In modern enterprises, IT environments of [&hellip;]","og_url":"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/","og_site_name":"Version 2","article_published_time":"2025-01-22T08:33:25+00:00","og_image":[{"url":"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-1.png","type":"","width":"","height":""}],"author":"tracylamv2","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"tracylamv2","\u9810\u8a08\u95b1\u8b80\u6642\u9593":"22 \u5206\u9418"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/#article","isPartOf":{"@id":"https:\/\/version-2.com\/2025\/01\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/"},"author":{"name":"tracylamv2","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/011bc7c3731c930bcfeecd52fefb6365"},"headline":"Cross-forest authentication with Thinfinity: secure multi-domain access","datePublished":"2025-01-22T08:33:25+00:00","mainEntityOfPage":{"@id":"https:\/\/version-2.com\/2025\/01\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/"},"wordCount":1318,"publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"image":{"@id":"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-1.png","keywords":["2025","Cybele"],"articleSection":["2025","Cybele","Press Release"],"inLanguage":"zh-HK"},{"@type":"WebPage","@id":"https:\/\/version-2.com\/2025\/01\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/","url":"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/","name":"Cross-forest authentication with Thinfinity: secure multi-domain access - Version 2","isPartOf":{"@id":"https:\/\/version-2.com\/zh\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/#primaryimage"},"image":{"@id":"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-1.png","datePublished":"2025-01-22T08:33:25+00:00","breadcrumb":{"@id":"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/#breadcrumb"},"inLanguage":"zh-HK","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/"]}]},{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/#primaryimage","url":"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-1.png","contentUrl":"https:\/\/blog.cybelesoft.com\/wp-content\/uploads\/2025\/01\/cross-forest-auth-1.png"},{"@type":"BreadcrumbList","@id":"https:\/\/blog.cybelesoft.com\/cross-forest-authentication-with-thinfinity-secure-multi-domain-access\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9801","item":"https:\/\/version-2.com\/"},{"@type":"ListItem","position":2,"name":"Cross-forest authentication with Thinfinity: secure multi-domain access"}]},{"@type":"WebSite","@id":"https:\/\/version-2.com\/zh\/#website","url":"https:\/\/version-2.com\/zh\/","name":"Version 2","description":"","publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/version-2.com\/zh\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"zh-HK"},{"@type":"Organization","@id":"https:\/\/version-2.com\/zh\/#organization","name":"Version 2","url":"https:\/\/version-2.com\/zh\/","logo":{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","contentUrl":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","width":1795,"height":335,"caption":"Version 2"},"image":{"@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/011bc7c3731c930bcfeecd52fefb6365","name":"tracylamv2","image":{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","caption":"tracylamv2"},"url":"https:\/\/version-2.com\/zh\/author\/tracylamv2\/"}]}},"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbQRKm-qwy","post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/101962","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/users\/149011790"}],"replies":[{"embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/comments?post=101962"}],"version-history":[{"count":7,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/101962\/revisions"}],"predecessor-version":[{"id":101969,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/101962\/revisions\/101969"}],"wp:attachment":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/media?parent=101962"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/categories?post=101962"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/tags?post=101962"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}