We have a project to move GP to the Cloud. The project where a vendor will a full Write/Read DC on their network which fully replicates with our DC on our on-prem infrastructure through an active dedicated VPN tunnel between them and us. To spin up the GP Web Client (version 18.5) it will require GPWebServices. To get GPWebServices to work properly, we need to add a Directory Security Store entry unto our Active Directories. We have several offsite colocations that hosts our Active Directory locally and performs replications through out my organization. My biggest concern, creating this AD record will propagate through my entire DC environment. I just don't know well enough about AD Security Manager and AD Security Store to weigh in the full security pros and cons on this. Unfortunately this dilemma is keeping us from moving forward with the project.
I could really use your isight and feedback on this. Has anyone ever set up GP Web Services and set up a Directory Security Store for GP? If you have, what security implications from your experience you can share with me.
I've included a Microsoft GP link concerning the requirement of GP Web Services needing a Directory Security Store.
https://community.dynamics.com/blogs/post/?postid=e9f4c209-9597-43fc-a681-bf7f94573bda