Question 1
A global organization is integrating their on-premises Active Directory with Workspace ONE UEM using the AirWatch Cloud Connector (ACC). The AD architecture consists of a single forest with a root domain (corp.local) and three regional child domains (na.corp.local, emea.corp.local, apac.corp.local). The administrator wants users from all domains to enroll using their UPN without installing an ACC in every child domain. What is the optimal configuration step to support this requirement?
Answer and explanation
Correct answer: A
To support users from multiple domains within a single Active Directory forest without deploying an ACC to each child domain, administrators should enable 'Multi-Domain' in the Directory Services configuration. Furthermore, the Server URL must point to the Global Catalog port (3268 for LDAP or 3269 for LDAPS). This allows the ACC to query the Global Catalog, which contains a partial replica of all objects across all domains in the forest. Changing the bind user format or adjusting sync schedules does not resolve the cross-domain routing limitation. Deploying standalone Access Connectors does not solve UEM directory integration.