This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

using AD users in clientless access or other rules when they never logged in before

Hi,

XG V17.5: How can I use an AD user in a rule when that user never logged in before?

I need to create that user manually in XG?

What's about password sync then?

any hints?

 

Best Gernot



This thread was automatically locked due to age.
Parents Reply
  • Thanks for answer.

    I tried around: Created a user in AD. Also created that user in Sophos and assigned it to the AD group (in Sophos).

    You can login with the password set in Sophos until you used ONCE the password from AD. So you can login with both passwords.

    Until the first login with the AD provided password the login with the sophos password is no more possible.

    This works as designed?

Children
  • So also that very usefull "preload" feature from UTM is (no more) available in XG. Right?

  • Hi  

    Basically there 2 approaches in user management.

    Either you can create a manual user or use import feature by adding user and required attributes such as password and group.

    You can integrate AD and use authentication when the user logs in by any method, it will create automatically in the Sophos XG but the user has to authenticate once but it is hassle-free to manage as you have AD in your network and you can import groups to XG firewall and you do not need to share the password to the user which is the case with manual creation.

    Whatever server you have select in the list, Local or AD, precedence will set accordingly.

    Regards,

    Keyur
    Community Support Engineer | Sophos Support
    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link