SSH, Windows, and Browser sessions are not appearing in Devolutions Server or RDM for non Adminstrators
DVLS Versions: 2022.2.6.0
RDM Version: 2022.2.29.0
Hello,
We are trying to configure RBAC for our various vaults and users are unable to see any sessions in the shared vaults when they are not Administrators. When looking at security permissions for the sessions in each vault, we see that the groups are granted all access to the sessions through either "custom" or inherited from the top level folder. Is their any additional configuration settings that need to be applied or is this a bug in the particular versions we are running.
Thanks
Josh
Hello Joshua,
It would seem that your user group membership is not working properly. Just to confirm, are you using domain authentication?
If so, could you go to the web interface of your Devolutions Server, under Administration > Server Settings > Authentication > Domain, and click on the Diagnostics button (top right corner):
Do a diagnostic type of "Get groups by user" test with the username of your choice (in the Parameter field) and change the "Principal" Strategy to "Directory entry token group" (the last one). If this one still fails, try with "Directory entry token group (Legacy)" or "Recursively".
Once you find one that works properly, go to the "Advanced Settings", and changed the strategy used to the one above for the "Get groups by user". Save and then try to use the test user again.
Let us know if it helps
Best regards,
Richard Boisvert
I tested "Directory Entry Token Group", "Directory Entry Token Group (Legacy)", and Recursively and all were successful. Is this possibly a configuration issue?
Hello Joshua,
If you head over to Administration > User Groups and click on the "View User Group Members" button, are your domain users showing up? Please note it will only list users that exists if Devolutions Server, it will not list all the users from AD.
If it is empty, it means the "Get Users by Groups" is having an issue after all.
If the users show up correctly, the permissions should apply. Would it be possible to head over to Reports > Data Source Logs, export the contents of the log and send it to service@devolutions.net. Please mention the URL of this forum thread as well.
Best regards,
Richard Boisvert