Home > Storage > PowerScale (Isilon) > Product Documentation > Management and Migration > PowerScale OneFS Authentication, Identity Management, and Authorization > Multi-instance Active Directory authentication provider
Previously, only one connection to a Microsoft Active Directory domain was allowed, and the name of the Active Directory provider had to be the same as the domain name. For the ZRBAC in OneFS 8.2 and later, a multi-instance Active Directory authentication provider allows multiple connections to a same Active Directory. Multiple access zones can create their own Active Directory provider, which connects to the same Active Directory, but each access zone can still have at most one Active Directory provider.
To use the multi-instance Active Directory provider, you must take the following actions when configuring the Active Directory provider in an isi CLI command or the WebUI:
In the isi CLI command, specify --instance and --machine-account options when using isi auth ads create. For example:
# isi auth ads create --name=example.com --user=administrator
--instance=example01 --machine-account=ad-zone01
The following figures shows the WebUI fields for specifying the instance name and machine account name:
Figure 36. Multi-instance Active Directory provider configuration