Symptom
We have multiple domains. Can we use SAML across all directories?
Resolution
Yes, you need to make sure that the domains are in a trusted relationship (bi-directional trust) with domain wide authentication. The following steps are needed:
1.) Conditional forwarding in the DNS for the root domain (domain.com) as the adfs server is named adfs.domain.com
2.) Adding the ADFS server name (adfs.domain.com) to the trusted sites in the Internet Explorer of the clients to make sure the windows authentication works
Keywords
KBA , BPI-SIG-CA-SEC-SAM , SAML 2.0 for SAP Signavio , How To
Product
SAP Signavio Process Manager all versions ; Signavio Process Manager all versions