cancel
Showing results for 
Search instead for 
Did you mean: 

User Group Security using Active Directory Groups

Patricia_Ritter
Champ on-the-rise
Champ on-the-rise

We're using Active Directory with OnBase 17. Currently our access is based on the user and use groups. Our goal is to let the AD Groups control our security. We have created the groups both in AD and in OnBase but I must be missing something. I have verified that my products, privileges ... are the same as my original admin user. When I sign in under the new authority of the admin group I have nothing available in the configuration.

1 ACCEPTED ANSWER

Patricia_Ritter
Champ on-the-rise
Champ on-the-rise

Adam ~ thank you so much. 

View answer in original post

6 REPLIES 6

Chad_Heskett
Star Contributor
Star Contributor
Did you do the group mapping in config?

Steve_McCune
Star Contributor
Star Contributor

under the user you are logged in as, under user settings, is User Group Administrator checked?

AdamShaneHyland
Employee
Employee

Hi Patricia.

As Chad had mentioned, if you had never configured the Active Directory integration within your system, you are going to have to map the user groups. 

Assuming you are using the Active Directory - Enhanced method, you will need to use the tool within Configuration (Config | Util | Directory Service Authentication | Settings) to map the Active Directory user groups to the OnBase user groups.  If the user group names are the same between AD and OnBase, this is simple as you "Auto-Configure using matching Group Names" option which will automatically map the AD group to the OnBase group as long as the names match.  If the names do not match then you will manually have to drag the user group from the Active Directory tree list to the user group in the OnBase user group list.

For more information, you can review the Active Directory Enhanced section of the Authentication MRG.  Also, there is a Quick Looks eLearning course available on Training.OnBase.com (https://training.onbase.com/courses/course?cid=E1208)

Best wishes.

Patricia_Ritter
Champ on-the-rise
Champ on-the-rise

A few years ago we went from LDAP to AD. I completed the necessary configuration tchanges but I haven't done anything since then. I do not have the option of (Config | Util | Directory Service Authentication | Settings) - this is due to the ~Romanzo switch not being turned on, correct? 

In the MRGs they keep mention AD Basic versus AD Enhanced. I believe we have AD Basic... is AD Enhanced something required on our side? Or is this just a setting that will choose once I have access to the above area? 

Thank you for your help.