AD adapter/Gateway configuration

Can the admin user used to start the gateway service be different from the admin user used by the AD adapter to provision AD accounts on the resource?

i.e. is having the gateway service running as Administrator and the IdM AD RA connecting to AD as idmadmin (an admin user set up for IdM use) a good or bad idea?

[325 byte] By [greenfan88] at [2007-11-26 9:20:53]
# 1

I don't know if it's a good or bad idea, but we do this. Our gateway is not a member of the AD (but is a trusted workstation), so we use a different AD admin.

We expect to be supporting multiple AD domains from the same gateway, so we built the gateway independent. We haven't done the multiple domains yet, but have had no AD problems with the primary one.

Chris_Stan at 2007-7-6 23:52:29 > top of Java-index,Web & Directory Servers,Directory Servers...
# 2
agree, we do this also.
glynns at 2007-7-6 23:52:29 > top of Java-index,Web & Directory Servers,Directory Servers...