Hi Team,
My corporate uses two AD systems that are linked together. We have created a new "Devolutions License Users" AD group that is nested in our Domain B. Within this new AD group, we have added specific users from both Domain A and Domain B. My goal is to ensure that when "Automatic User Creation" is enabled that Devolutions will be able to add users between both domains. I would assume it goes by whatever "Active Directory Domain Services Folder" that user belongs to. In other words, I should not need an AD group for each domain based on user since the domains are crosslinked already.
Also, I want to note the inefficiency adding my new AD group to the "Automatic User Creation". Our corporation is very large, with thousands of AD groups. At least for "Automatic User Creation", Devolutions Server does not allow typing in the AD group to the "Only from this group" section, and instead you must scroll until you find the exact group you want. What's worse, the groups naturally aren't populating quickly due to the sheer amount that must be generated over the net. I would be so very thankful if you could modify this to allow typing of the actual AD group. You already allow this in "Administrator > User Groups" so I felt this was a miss within "Automatic User Creation".

82f77ff8-b409-4d91-af2d-3643df258554.png
c2fa716b-091f-4878-adc5-fa0046c3aa90.png
I did some testing with Automatic User Creation and unfortunately have found that the user has to be in the immediate root level of the Domain Container (cannot be within a group within the container) for it to work.
I am sure I'm overlooking something and would appreciate any advice and help.
Key points:


57fe4c31-6535-4d5d-8735-d3d3ebdff69e.png
5db5f17c-d538-42fd-86ee-43c860188806.png
Hello,
Thank you for reaching out!
My name is William and I'm here to assist you in any way I can.
I've verified and it is possible to search for a specific group within the Only From this Group:
As for your configuration, could you try the diagnostic Get All User with different strategies?
Also, could you confirm if your two domains are in a forest? If so, you should be able to configure one domain authentication in DVLS to the root domain and then read the subdomains for the authentication.
If the two domains are not related and only have a trust between them, then it is possible that it might not work. We will need to test using different strategies.
Best regards,
00ef0cc9-ceca-4da5-ba9e-323f73f185aa.png
Hello,
Thank you for reaching out!
My name is William and I'm here to assist you in any way I can.
I've verified and it is possible to search for a specific group within the Only From this Group:
As for your configuration, could you try the diagnostic Get All User with different strategies?
Also, could you confirm if your two domains are in a forest? If so, you should be able to configure one domain authentication in DVLS to the root domain and then read the subdomains for the authentication.
If the two domains are not related and only have a trust between them, then it is possible that it might not work. We will need to test using different strategies.
Best regards,
@William Alphonso
The issue with the "Active Directory groups" search feature is that on very large domains, with numerous containers and groups, DVLS attempts to first read the entire directory instead of letting you search first instead. This results in numerous timeouts and waiting multiple minutes or longer. Attempting to use the search feature is painful and slow. You generally have to click and start typing while not seeing anything, then wait 30 to 60 seconds longer before you see your text. I would highly advice you to add a feature that allows you to search first and a button to poll if you want otherwise.
Hello,
Thank you for the confirmation. It is also possible to reduce the size of the search by Devolutions Server under Administration > Server Settings > Authentication > Domain > Advanced Settings > Domain Containers. This will limit what DVLS can see in your domain, which should accelerate the process in bigger environment.
Best regards,
de353031-5a72-435a-8f80-a59d8ca7987c.png
Hello,
Thank you for the confirmation. It is also possible to reduce the size of the search by Devolutions Server under Administration > Server Settings > Authentication > Domain > Advanced Settings > Domain Containers. This will limit what DVLS can see in your domain, which should accelerate the process in bigger environment.
Best regards,
@William Alphonso
Thank you. I have previously done this and while that “helps” it’s still painful since our organization is extremely large. Having the option to decide between search or poll would be best. Please submit this as an improvement feature (or something similar).
Hi Team, I am making some progress:

From Administration > User groups, I have my "Devolutions License Users" group populated. It does read users from the group but only displays those that are already in Administrator > Users.
Currently I am getting this error with attempted logins by new users that are in "Devolutions License Users". I would expect the behavior would be to auto-create their account on first login. Am I thinking about this wrong here?
d07c0f92-b2c0-4f2b-9b70-89077259ea39.png
44a11770-247f-469c-8336-9871cfaead2f.png
Hello,
Would it be possible to confirm if the Auto-create on first login enabled on the domain or subdomain configuration?
Also, it is not necessary to have the Devolutions License Users under the User Groups of Devolutions Server. The groups imported there will not automatically import the members and it is mainly used for permissions.
Best regards,
Hi @William Alphonso and thanks for the reply. My domain structure looks like this:
Master Domain

Domain Settings:
Strategy on both Subdomain A and B are set to like so:
42ea6b84-1452-457c-a1e3-711422a0a3cb.png
e97e06ea-ac69-4308-8c88-4ab4a1a58dd8.png
On a second but similar topic, after manually adding users, I had two teammates log into DVLS via SSO to test the "Automatic License Assignment", then log out. Unfortunately for my case, auto license assignment is also not working. I ended up having to manually assign the licenses to them. I have it set to wide-open, so my thinking is that it should be automatically assigning these licenses.
35e3f5bf-c410-48df-b0d7-2fdf71e6678b.png
Hello,
Just to be certain, here's how I see your configuration:
Can you confirm if these works with your current configuration:
What I'm expecting here is that users from DomainAB and SubDomainA will not be automatically created but users from SubDomainB are automatically created. If this is the case, could you try enabling the auto-create on first login on SubDomainA and see if users from SubDomainA can now be automatically created?
As for the automatic license assignment, it will be done when a user logs in from Remote Desktop Manager (RDM) and not from the web interface. I've tested this and the license is only assigned when I authenticated through Remote Desktop Manager (RDM) or Devolutions Launcher. I will poke our development team to see if this is the intended behaviour.
Best regards,
@William Alphonso
That is good to hear on auto assignment of license when logging in via RDM for the first time. I'll test that and let you know.
You are correct with #s 1, 2, and 3 on the configuration.
For 4, 5, and 6: No users are being automatically created. You would expect with #6 (SubdomainB) that users would be automatically created. DVLS diagnostics can see all users within my "Devolutions License Users" group. Both SSO and manual domain login is working for existing users to log into DVLS so that's not the issue.
Below are the errors I am setting on login attempts from two different users within that group:
6ab96278-f57d-4943-a545-6f79d0ce61a4.png
@William Alphonso for the auto assigning of the license, it is not working with attempting to login with RDM:
7cf9e6b6-408d-4480-a087-6be1d9626953.png
Hello,
Just as a test, would it be possible to create the service accounts for AD authentication and the Devolutions Licensed Users in the root domain instead of one of the subdomain and see if the auto-create on first login works this way?
As for the auto assignment of license I would prefer to wait until we can fix the authentication first.
Best regards,
@William Alphonso, I left enabled "Automatic User Creation" and did not enable the "Only from this group" and I was successful in logging into DVLS with my alternate admin login! So that is some good news. Now we just need to figure out why not from groups and only from containers. :)
Hello,
Thank you for the confirmation. In that case, we would need to figure out where the search for the group and it's membership is failing.
Would it be possible to confirm the following:
Please don't hesitate to reach out if you have any questions or need further clarification.
Best regards,
@William Alphonso thank you, I will start testing this tomorrow.
Note, I was able to add my "Devolutions License Users" to another group I had (the one I informed you earlier worked for automatic user creation) and this allowed the automatic user creation to work with those in the "Devolutions License Users" group. At the very least, we have a workaround for now. :)
Hello,
Thank you for the confirmation. Would it be possible to confirm where that working user group is located in your AD (Root domain, subdomain A or B)?
Best regards,