Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationHow to restrict or allow access only to a particular OU in ADHow to restrict or allow access only to a particular OU in AD
Previous
 
Next
New Post
10/25/2006 7:01 AM
 

How can I allow users from one OU (organizational Unit) in Active Directory to access the DNN website.  All other users should be denied access.  eg ou=TestOU1 need to be allowed the website any other OU should not be allowed to access.

Is there a way I can do this? 

My specs: DNN 3.3.4, SQL 2000, Windows 2000

Early help appreciated.

 

 
New Post
10/25/2006 11:34 AM
 

Use the Security Roles.  They should automatically be populated with identically named user groups in AD.  Then, permit only certain roles to view the website.  Do a "select all" in the AD OU, and add all members to that new group you just created.

It's not a total denial of login, but they'll basically get a blank page if they're not part of the right AD group.

 

 
New Post
10/25/2006 11:48 AM
 

Thanks, DanBall.  However I have some questions:

Would the restricted users from the AD be still added to my site?

Is there a way to show a page with some message instead of a blank page?

Also, is there way to have total denial?

 
New Post
10/25/2006 2:06 PM
 

I do not know of any way to do total denial by AD settings...  Due to the design, it appears to me it is an all-or-nothing type of system.  Possibly you can seperate it down to individual forests, but then your AD settings would be problematic.  Anyone that is part of the domain will have an account automatically created for them in DNN.  They may not be able to do anything, but the account will be there.

No, you don't have to have a blank page.  Each module on each page is totally configurable (by security role) as to who can see what, who can do what, etc...  In other words, you can have the same page look completely different simply by what group they are in. 

 
New Post
10/25/2006 4:15 PM
 

Thanks DanBall, I figured out the page settings. Your suggestion for the roles sync with AD will work now.  Only thing is i need to figure out a script to move all the users that dont belong to the specified OU to Unauthenticated role.  May be i will run this script periodically and then delete those unauthenticated users.

 

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationHow to restrict or allow access only to a particular OU in ADHow to restrict or allow access only to a particular OU in AD


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out