# Mulitple domains

**URL:** <https://discuss.elastic.co/t/mulitple-domains/24633>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 30, 2015, 2:33pm UTC](https://discuss.elastic.co/t/mulitple-domains/24633 "2015-06-30T14:33:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![matt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt/32/524_2.png) [@matt](https://discuss.elastic.co/u/matt)\
**Post date:** [June 30, 2015, 2:33pm UTC](https://discuss.elastic.co/t/mulitple-domains/24633/1 "2015-06-30T14:33:26Z")

</div>

Hi guys,

Quick question regarding Shield. We would like to use Shield to authenticate users using Active Directory. But the users are part of different domains. The current documentation shows that the domain\_name is fixed in the configuration file.

Is there a Shild API that allows me to pass user/password/domain information to get authenticated? If not, how can I achive this for our setup. Please advice. Thanks!

Matt

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 30, 2015, 6:06pm UTC](https://discuss.elastic.co/t/mulitple-domains/24633/2 "2015-06-30T18:06:45Z")

</div>

Hi Matt,

We do not have an API that lets you pass in credentials with a domain right now. You can configure a realm for each AD domain that you have, but each one will be tried in order so it will add additional time to authenticate and some load to you active directory servers. Do you use nested groups? If not, you may be able to just use the regular LDAP realm and configure it to query the global catalog of your active directory and only need to configure that realm.

One of the enhancements that we've got on our roadmap in the ability to test based on the credentials if we should try to authenticate to a domain. For example, if you passed in `DOMAINA\user` then the AD realms would check to see if it was for `DOMAINA` before attempting authentication otherwise the realm would skip it and move on to the next one.

-Jay

---

<div class="post-metadata">

**Author:** ![matt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt/32/524_2.png) [@matt](https://discuss.elastic.co/u/matt)\
**Post date:** [June 30, 2015, 6:47pm UTC](https://discuss.elastic.co/t/mulitple-domains/24633/3 "2015-06-30T18:47:51Z")

</div>

Jay,

thanks for the quick response. I have just opened a dev\_support ticket with you guys (#10935).

I don't think checking each user name again different domains would be an ideal solution. Best case is that you get authenticated in the 1st try and the worst case is your domain is on the very last line of the lookup (henice the login process might timeout).

Any ETA on this enhancement? Thanks!

Matt

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 1, 2015, 11:17am UTC](https://discuss.elastic.co/t/mulitple-domains/24633/4 "2015-07-01T11:17:01Z")

</div>

I don't have a timeline on the enhancement at the moment, but maybe through the dev ticket we can figure out a solution.

-Jay

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:49pm UTC](https://discuss.elastic.co/t/mulitple-domains/24633/5 "2017-07-06T13:49:01Z")

</div>


