Forum Discussion
APM Access Policy - Pass LDAP or AD Query variable
Thank you for your time and answer....that helps solidify what I thought I knew...my problem is that the branch rule that I try doesn't work the way it should for a known good...
Branch rule: expr {[mcget {session.ad.session.ad.last.attr.variable1}] != "" || [mcget {session.ad.session.ad.last.attr.variable2}] != ""}
For my test account there is a value for variable 1, but the debug logs say that it can't be found nor is it memcached.
What am I missing?
If you get a log that the variable is not found, then the AD Query agent must not have created it. The LDAP Search performed by AD Query includes a default attribute filter that you can adjust or remove. By default only these "Required Attributes" are returned by the search:
So if you need additional attributes than these, you can add them.
- jamie_staplesMar 15, 2023
Cirrus
If the additional attributes ARE among the required attributes, and I am still getting the variable is not found, what do I do?
If I have removed some of the "required attributes", does that break something? Do I always have to use the specific required attributes AND any additional attributes?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com