Limit Login Access to AD User Groups

Limit Login Access to AD User Groups

avatar
cathans01
Disabled

It seems as of now the two choices for user account creation are:
1 - Create users manually to allow access
2 - Allow AD Auto-Creation by any valid domain login.

Is it possible to require a specific AD Group membership in order to login--irrespective of the AD Group <-> Rights Membership groups? The end result would be that the 'public' or non-security group controlled contexts would only be visible to users that were part of the original AD Access group rather than just anyone with a valid AD login.

All Comments (7)

avatar

Good idea. I will add this to our todo list.

Regards

David Hervieux

avatar

How can I allow users from AD Security group to access Devolutions server thru RDM Client (without adding users manually). Like instead of adding users manually (one-by-one) how can I grant access to Datasource using AD Security group.

For now I a am able to grant access to individual AD users to the datasource.

avatar

Hello,

To allow users from AD Groups to access Devolutions Server automatically, you have to activate the Auto create domain users in database option in the Authentication tab of the Server Settings.

Best regards,

Érica Poirier

2016-10-17_8-05-52.png

avatar

Thanks a lot for response Erica.
What if I have 2200 Users, dose that option create 2200 users in DB(SQL Server), or you are referring to some other database (Devolutions DB)

avatar

Hello,

This option will create the user on his first login to the Devolutions Server.

In the next version of Devolutions Server, there will be a tool to do a massive import and creation of AD users.

Best regards,

Érica Poirier

avatar

Hello Team,

How can grant access to users using RDM on Datasorce from other domain (xyz.com) trusted to Devolutions Server domain (abc.com).
I want all users from xyz.com domain accessing datasource (Devolutions server) installed on abc.com domain.

Note: xyz.com--TRUST RELATIONSHIP--abc.com

avatar

Hello Aammir,

As Maurice's response into that topic (https://forum.devolutions.net/topic26262-windows-active-directory-integration.aspx?lastpage=1#post98493)






I hope that answer will help you.

Best Regards,

David Grandolfo