Forum Discussion
fwebb_116789
Nimbostratus
Sep 17, 2014APM authenticate user to multiple AD groups
Hello All:
I hope someone can help me with this. I have recently deployed a private cloud on vCloud Director 5.5. We run a Development and Test Lab that have multiple projects running at any g...
- Sep 22, 2014
Did you try to work with the option "Nested Groups" in your AD authentication ?
It will help you to avoid this kind of problems as for each group, the APM will check your conditions.You would have to define only one ressource assign box with your groups membership conditions.
Here is a solution link to use nested groups : http://support.f5.com/kb/en-us/solutions/public/12000/100/sol12193
Thomas_Gobet
Nimbostratus
Sep 18, 2014On which version are you running on ?
Also, why do you use the same macro whether the result is "Success" or "Fail" ?
I think you can optimize it, the problem is just to understand every scenario you can encounter.
- fwebb_116789Sep 19, 2014
Nimbostratus
Thomas, I am running version 11.4.1 HF4. I use the same macro to avoid having to define the Member of for the AD Query. Each branch represents all the possible combinations of group memberships. In the example above, I have 5 groups: Admin, 3, 8, Applications and Models and Simulation. There were only be Administrators accessing Administrative assets. After that though, depending on who the user is they could be members of any combination of groups based on what they need access to.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
