Hi Phil,
also when already answered there are multiple options within Dir Sync:
1. You can add multiple Directories and they will be searched in the Order you have defined
2. If you have an Forest you can also add the Global Directory on Port 3389(should be correct) when your AD is organized in a logical structure wihtin Forest
3. Multiple forests is also possible but I recommend having no duplicates
- Super Silent Enroll uses per default the Samaccountname so be aware if it finds it in the directory it will try to authenticate it in the first directory where it succeds
- Silent Enrollment: Gives you the abiltiy to utilize the upn which can be even added as search filter in the universal Dir Sync Configuration:
- This allows you to speed up the enrollment since not all AD's will be searched when the filter matches
- Last but not least you can utilize Directory Custimization: But this should be conducted with a Partner or an Admin who is familiar with this modification
So i have iplemented myself multiple directories utilizing all methods I mentioning here and they usually work wonderfull within the envrionment you have.
Be aware Dir Sync is so smart and caches where it found the user the first time and is utilizing this for further lookups. So be aware that you might have only a slower response time for enrolling when you need to go down one by one.
It really needs to be remembered when you add 20 Directories and the user is in NR. 20. It will search the other 19 first until it has found him.