Caveats
The isolation of the components in a given Secure Access Site means that a specific VA will only be aware of users who have authenticated against domain controllers assigned to the same Secure Access Site. As a result, we do not recommend using multiple Secure Access Sites in a single AD site, even if that AD site spans multiple geographical locations. In such a scenario, users in a location may still authenticate against a DC in a different location, and thus the Secure Access components may miss user mappings.