Forum Discussion
smp_86112
Cirrostratus
Nov 20, 2007System -> Authentication -> Remote - Active Directory
I am trying to configure our 9.3 LTM System Authentication to use "Remote - Active Directory". The question I can't seem to get a straight answer to is whether the LTM can look at Active Directory group membership to authenticate a user. In my case, there are two crucial considerations:
1) The user accounts who are members of my management Group may not all be in the same OU
2) The user accounts who are members of my management Group are not in the same OU as the Group.
Is this architecture possible, and if so, can you provide specifics or a cleansed example of how the Authentication Configuration screen on the LTM (or GTM or whatever...) should look?
Thanks.
- Mark_Curole
Nimbostratus
I use the same kind of configuration. BigIp does not use AD for authorization only authentication. You have to add the users you want to have access inside BigIp, one at a time. - smp_86112
Cirrostratus
Thanks for your reply. - JRahm
Admin
The lack of authorization has been a glaring shortfall for me as well. I had hoped that with their new administrative domains in 9.4 that this would be addressed, but without remote authorization support, the load on the administrator is even heavier if you choose to use the partitions.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects