Forum Discussion
Grayson_149410
Nimbostratus
Nov 08, 2016APM LDAP Auth Using Email Address
We are in the process of moving away from one HR system to another. By doing this, all of our warehouses users need to be able to log into some Sharepoint sites occasionally. We already have this se...
Michael_Jenkins
Cirrostratus
Nov 08, 2016I just finished doing something similar. Essentially I modified the policy to allow
domain\username, username (using default domain), and email. Since you're asking about just email, I'll explain what I did there. (Note: we use AD instead of LDAP, but this is how I think it ought to work for you)
After the
Login Page action, I would use the LDAP Auth action to search for the user. I would set the SearchFilter to (mail=%{session.logon.last.logonname}) and the root LDAP DN in the SearchDN.
From there, use an
LDAP Query action with the same SearchFilter and SearchDN and add whatever attributes you'll need (i.e. samaccountname).
From there, you can add an
SSO Credential Mapping object using session.ldap.last.attr.sAMAccountName for the SSO Token Username property (may show up in the drop down there).
Hopefully that will help.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects