Does anyone use Enterprise Connect or the Apple SSO Extension in an environment with multiple realms? and how do you deploy this out or configure it?
For example, we have our user ids in different dc's or realms (excuse my lack of AD knowledge), so if my user id is XX1234 and I belong to US3 realm, (we currently use NoMAD) so my realm would be us3.dc.corp.com that will let me use my user id of XX1234.
if I tried just corp.com it won't work as the nomad or SSO tool will think the account is XX1234@corp.com, I tried a few variations of it too: dc.corp.com (thinks the username is xx1234@dc.corp.com) and so on.
I opened a case with enterprise support, but so far their engineers dont think its possible to identify multiple realms. inside the config profile you can technically create additional REALM entries but it seems to pick a random one and does not really function how I'd hope it would.
the other solution is just making multiple config profiles available via self service to our users to install as I dont see a way in Jamf to scope to a Domain or DC natively.