SSH, Windows, and Browser sessions are not appearing in Devolutions Server or RDM for non Adminstrators

SSH, Windows, and Browser sessions are not appearing in Devolutions Server or RDM for non Adminstrators

avatar

DVLS Versions: 2022.2.6.0
RDM Version: 2022.2.29.0

Hello,
We are trying to configure RBAC for our various vaults and users are unable to see any sessions in the shared vaults when they are not Administrators. When looking at security permissions for the sessions in each vault, we see that the groups are granted all access to the sessions through either "custom" or inherited from the top level folder. Is their any additional configuration settings that need to be applied or is this a bug in the particular versions we are running.

Thanks
Josh

All Comments (3)

avatar

Hello Joshua,

It would seem that your user group membership is not working properly. Just to confirm, are you using domain authentication?

If so, could you go to the web interface of your Devolutions Server, under Administration > Server Settings > Authentication > Domain, and click on the Diagnostics button (top right corner):
forum image

Do a diagnostic type of "Get groups by user" test with the username of your choice (in the Parameter field) and change the "Principal" Strategy to "Directory entry token group" (the last one). If this one still fails, try with "Directory entry token group (Legacy)" or "Recursively".
forum image

Once you find one that works properly, go to the "Advanced Settings", and changed the strategy used to the one above for the "Get groups by user". Save and then try to use the test user again.
forum image

Let us know if it helps

Best regards,

Richard Boisvert

avatar

I tested "Directory Entry Token Group", "Directory Entry Token Group (Legacy)", and Recursively and all were successful. Is this possibly a configuration issue?

avatar

Hello Joshua,

If you head over to Administration > User Groups and click on the "View User Group Members" button, are your domain users showing up? Please note it will only list users that exists if Devolutions Server, it will not list all the users from AD.

If it is empty, it means the "Get Users by Groups" is having an issue after all.

forum image

If the users show up correctly, the permissions should apply. Would it be possible to head over to Reports > Data Source Logs, export the contents of the log and send it to service@devolutions.net. Please mention the URL of this forum thread as well.

Best regards,

Richard Boisvert