Active Directory Trusts and Foreign Security Principals

Active Directory Trusts and Foreign Security Principals

avatar

Hi all,

Please help if this is a bug or a current limitation of the product.

When using Domain Diagnostics (Administration -> Sever settings -> Authentication -> Domains -> Medkit Icon) for ex. using "Get users by group", then foreign security principals are correctly listed. Meaning the software lists the Distinguished Names of the users which may originate from several different domains in another Active Directory forest (full transitive Trust between both forests) beloging to this group.
However when then trying to use those Active Directory groups in Devolutions Server, the software will suddenly not recognize that the users originating from a foreign forest (those users were also Auto-Created by a login from the connected foreign forest) are members of the group which showed them as being members through diagnostics. If you click on the user the group membership is not selected, only members from the same domain as the group show the group as selected.

Another limitation is that the Auto-Create User group limitation on Active Directory domains only seems to work with a group from the same Active Directory domain as the connection, also making things more difficult to manage, as this would now suddenly require 7 differnent groups in 7 different domains in 2 forests to achieve what is currently possible on the MSSQL database with just one AD group which contains all users from any domain and forest.

Please advise.

Regards

All Comments (1)

avatar

Hello,

Thank you for contacting us on that matter.

For the group membership, I have been able to get it working by setting the Get groups by user domain strategy to Principal in the Domain Advanced Settings.

These are the domains configured on the test DVLS I use.



For the downhill.loc domain, I set the Get groups by user to Principal as explained above.



As a result, the Downhill test1 user is now a member of the testgroup6 group from the Windjammer domain. It also works if only the Downhill domain is configured in DVLS.



I found this setting using the Get groups by user diagnostic type from the Downhill Domain diagnostic tool.



For the automatic user creation, DVLS actually manages domain authentication per domain. The scenario you expect to get requires a configuration per domain for the authentication process. If you have 7 different domains, you need to configure all of them in DVLS.

Let us know if that helps on your end.

Best regards,

Érica Poirier

577f9bea-7a7b-4d3b-9ed7-bc576232cc85.png

1aff5471-beff-4576-bcc2-49e32e4ccf1e.png

6129d906-0fea-4c77-883a-ffe043a18e2a.png

20c96f1f-193f-4f28-9f0c-04bfa8515d7e.png