Discovery of the second domain
Now that both organisations have been added to the Secret Server instance it is time to start the Discovery of the domains.

To be able to manage the second infrastructure via the DE, discovery needs to be configured for the Greensafe.lab domain. After the discovery of Machine, Dependencies and Accounts the next configuration step can take place, defining the correct access rights to the Domain admins of the two different organisations.
Adding secret for AD Sync Greensafe
- Log out of the db-server
- Switch back to the SSPM server and refresh your browser
- Login as ss-admin (as we have been logged out due to the login on the db-server, re-login is needed)
- Navigate to Secrets >> > TSS Service Accounts and add a new secret by clicking the + sign in the top top right corner next to the SS icon

- Make sure the template to use is Active Directory
- Use the following parameters
- Secret Name: AD Sync Greensafe
- Domain: greensafe.lab
- Username: cfyadmin
- Password: Centr1fy
- Notes: Account used for Discovery Scan Greensafe
- Site: greensafe.lab
- Click Create Secret
Configure Directory Service Greensafe
- Navigate to Administration >> > Users, Roles, Access > Directory Services
- Click Add Domain > Active Directory Domain
-
Use the following parameters
- Fully Qualified Domain Name: greensafe.lab
- Friendly name: Greensafe
- Synchronization Secret: AD Sync Greensafe (be patient to get the full list of secrets available)
- Site: greensafe.lab

-
Click Validate & Save
- In the groups select the following groups:
- Domain Admins
- Team_Auditors
- Team_Contractors
- Team_Finance
- Team_Helpdesk
- Team_IT
- Team_Sales
- Team_Security
- Team_UnixAdmins
- Team_UNIXDBA
- Team_WindowsDBA
- Run Sync Now
Configure and run Discovery Scanner for Greensafe
- Navigate to Administration >> > Actions > Discovery
- Click Create Discovery Source > Active Directory
-
Use the following parameters
- Discovery Source Name: greensafe.lab
- Fully Qualified Domain Name: greensafe.lab
- Friendly name: Greensafe
- Discovery Secret: AD Sync Greensafe
- Discovery Site: greensafe.lab

-
Click Create
-
In the next step, under Find Dependencies, select all options

-
Click Save
- Navigate back to Administration >> > Actions > Discovery
- Click Run Discovery Now > Run Discovery Scan
-
Wait till the status from Running has switched to Last Run: Just Now

-
Repeat the same steps, but now Run Computer scan, this will detect local accounts
See the discovered accounts
- Click Discovery Network View
- You should now have two domains being mentioned
-
Expand both domain and have a look around. Click the tabs (Local Account, Public Keys, Service Accounts and Domain\Cloud Accounts) all should have some info.

-
This means the Discovery scan has run successfully and Secret Server can now start to control the accounts.