Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationAD Provider - Synching Administrator AccountsAD Provider - Synching Administrator Accounts
Previous
 
Next
New Post
8/28/2009 10:16 AM
 

I am having trouble synching the administrators group from AD to DNN.  DNN 5.1.1, AD Provider 5.0.2.  I'm resolved to using the WindowsSignin.aspx to auto-login Windows users at this point, though this may change if I get the impersonation configured.  Synchronize Role is checked.  My issue is this:

I create a group in AD such as DNNUsers and create the same group in DNN as a Security Role.  I add a user to this AD group. I log in to the Windows workstation as this user and browse to the WindowsSignin.aspx file.  The user account is automatically created in DNN and the user is added to the DNN Security Role that matches the AD Group.  Everything appears to work fine.

Except if I have a user in the AD Administrators group, they are not given the Administrators role in DNN.  Is there something special about this role/group that prevents this?  The user account is specifically in the AD Administrators group, not a group like Domain Admins that is a member of the Administrators group.  Is there a work-around to provide an AD group that would map to the DNN Administrators role?

Thanks,

Jeff

 
New Post
8/30/2009 5:47 PM
 

Administrators have to be manually added to the role. If not, with the nest role search, anyone who was in the Domain Administrators group would also get added to the DNN administrators group. In most cases you only want a small group of people actually able to make changes to the website and not just anyone who may have admin rights in the AD but have nothing what-so-ever to do with the website.

 
New Post
8/31/2009 3:12 PM
 

Adding nthem to the role means I have to have them log in first to create the account automatically.  Not the best option, but understandable, thanks.  Guess I was think AD authentication would actually be AD integration, but it isn't.

Jeff

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationAD Provider - Synching Administrator AccountsAD Provider - Synching Administrator Accounts


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out