Global catalog search and roles for Active Directory

My IT group is suggesting I ask someone here how to use the global catalog, as the example configurations show a search base which apparently restricts to a single domain. The primary AD group with all the application users are spread across several domains.

Separately, we would want to have select users having different roles in the Atlas application. Since we don’t have AD working yet, I’m not sure if it makes sense to create different AD groups to map to different roles or what the best approach is.

My last question is if we point to an encrypted port, will that work or are additional steps needed to make that happen?