You are not logged in.

Announcement

 Téléchargez la dernière version stable de GLPI      -     Et vous, que pouvez vous faire pour le projet GLPI ? :  Contribuer
 Download last stable version of GLPI                      -     What can you do for GLPI ? :  Contribute

#1 2021-09-10 11:18:14

jakonda
Member
Registered: 2021-09-10
Posts: 2

How to configure synchronization AD users into AD groups ?

Hi,

I am stuck and i need a community help. Here is discribe of my problem:
I have AD users and AD groups in the different OU (ex. Users - OU=Users,OU=Moscow,DC=Contoso,DC=local; Groups - OU=GLPI,OU=Groups,OU=Moscow,DC=Contoso,DC=local), so i make two LDAP connections, 1st - for the import users, 2nd - for the import Groups.


1.png

Users connection:

2021-09-10-120103.png
3.png
4.png

That connection works perfectly fine, as result i`ve successfully imported all AD users.

Group connection:

5.png
6.png
7.png

That connection as User connection works fine. All groups in indicated OU has been seen and imported.

8.png

But if we go to any of these groups, we will see an emply list of user members.

9.png

Of course these groups contain users that exist in the user list.

So there is my question - what am i doing wrong ? And how to properly synchronize user membership in groups ?

Please help guys

Offline

#2 2021-09-15 14:10:08

WebGreg
Member
Registered: 2020-02-27
Posts: 740

Re: How to configure synchronization AD users into AD groups ?

Did you try login on one of the user from group. I think you will see him in group after first login.


--
GLPI 10.0.17
GLPI-Inventory 1.4.0
Ubuntu Server 20.04 LTS

Offline

#3 2021-09-15 17:25:37

jakonda
Member
Registered: 2021-09-10
Posts: 2

Re: How to configure synchronization AD users into AD groups ?

WebGreg wrote:

Did you try login on one of the user from group. I think you will see him in group after first login.

yes i did that, but imported groups still empty, i can not understand how it should working.

Offline

#4 2021-09-16 08:44:50

WebGreg
Member
Registered: 2020-02-27
Posts: 740

Re: How to configure synchronization AD users into AD groups ?

Strange. I just tested it - after importing, I also have no users. But when I logged in - my user shows up in the Users tab. It's normal behavior. I didn't do anything more than import the group and login.

Maybe its something global what I set early... "Authorizations assignment rules"? Or more likely on setup.auth.php > Setup:

Automatically add users from an external authentication source - Yes
Action when a user is deleted from the LDAP directory - Disable
Add a user without accreditation from a LDAP directory - No


--
GLPI 10.0.17
GLPI-Inventory 1.4.0
Ubuntu Server 20.04 LTS

Offline

#5 2022-12-02 20:40:12

lexcyr
Member
Registered: 2022-12-02
Posts: 8

Re: How to configure synchronization AD users into AD groups ?

Hello,
I think i have the same issue. i have manually import my group from AD and i don't understand how to make it works.
when i try to login with a user from that group i have the user added automaticaly in the users list, but not under his group. i feel like i have an issue in the group filter under the LDAP configuration.
In my case i don't have 2 LDAP configuration. I just have one LDAP configuration :
image.png

image.png

What i am doing wrong? The main objective is to be able to assign profile to members bases on their AD groups.

Thanks in advance for your help.

Offline

Board footer

Powered by FluxBB