I have a number of posts on this question. I wanted to include it as a wish item, but realized I can't add the item. So, with that being said, let me describe what I would like.
I am looking for a solution that will permit my end users to login to any business space where they have permissions and use their current windows login credentials.
I have been given some details from support on how I can kind of do this. One way is to add attributes to Active Directory to identify which BS a person can access. I really don't want to manage anything other then login and password within Active Directory.
What I would like is a solution where by I can use existing Active Diretory logins & passwords as a way to authenticate users. I realize that I then would need a way to map a user to a specific security profile. I would like to do that via AwareIM.
Let me give you an example of an application we purchased that works in a similar fashion. The product is called MasterControl. It is a document management system. IT has a LDAP interface. The system permits you to setup LDAP settings within the application configuration. Basically you point the MasterControl system to the LDAP server and provide some basic configuration information. Once those settings are set, you can establish a frequency in which you want the LDAP "imported". Once someone has been imported, you can then associate a "Access Level" to that login.
So, with the above solution, everything is managed within Mastercontrol except for the login id & password which are hosted in LDAP, but imported into Mastercontrol.
I have seen this type of functionality in a few applications that I have recently reviewed or used. Hopefully this can be included in one of your new builds.