Thanks Localzuk. It is making sense to me. I am a network guy and not windows admin, so I have very limited knowledge on window NOS side.
I believe on an existing W2k3 domain controller, we can certainly add another domain for mac address users ( and have two way trust between these two domains), but then how does the IAS talk to two domains on the DC? IAS will be enrolled / registered with only main domain and thus forward requests only to main domain. I guess then DC has to somehow pass on the credentials to the second domain database, but then it will fail as seocnd domain database will see domain name appended to credentials being the main domain name.
Just as a curiosity, is there a way to add local user accounts (in this case mac accounts) to switch and then use local authentication?
Please advise.
Thanks