Forum Discussion
Sending APM AD Query groups as a header
Better play an test to make it work as I have not done this myself but you can also try session.ad.last.attr.primaryGroupID https://techdocs.f5.com/en-us/bigip-15-0-0/big-ip-access-policy-manager-visual-policy-editor/per-request-policy-item-reference/about-per-req-authentication-items/about-ad-group-lookup.html
Other than that to make it more secure better use F5 Bearer SSO JWT sign in than HTTP header as F5 can provide the groups in the JWT token that is signed by an F5 Cert that the applications can also have.
The only thing is I'm not using the primary group. I'm changing the branch rule to branch rule 1 CN=AD group i'm checking against for membership and permissions to the application.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com