This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Client Authentication Agent causes user's group to reset to "Open Group" on login.

I have a number of users divided into different groups with different access and time limitations.  I've found that whenever a user logs in using CAA on Windows, their group changes back to the "Open Group".

All the users in question are authenticated via LDAP and the Open group is the default group.  However, that seems like it should only apply to their first login.  After their account is created in XG, the assigned group should stay and not be reset during an authentication action.



This thread was automatically locked due to age.
Parents
  • Hi Troy ,

    When you configure the LDAP server on XG with successful test, connection  You would need to import the Groups first as indicated on the left of your LDAP server list.  Refer article https://community.sophos.com/kb/en-us/123158 for your reference.

    After the Groups are being Imported , The Open Group would be at the top most position . We would need you to reorder the Group and Assign the Open Group at the bottom of the imported Groups  . 

    This should resolve your issue.

    Thanks and Regards

    Aditya Patel | Network and Security Engineer.

  • Hi Aditya,

    Even after reordering the groups as suggested in your post, user's are getting reset to (in my case default user group) --Domain Users. In AD I have created a separate group/OU for Managers and separate group for Users. I suspect that CCA is causing the reset of managers to domain users.

    I have imported group successfully on XG referring https://community.sophos.com/kb/en-us/123158 . Please suggest a permanent solution to stop users under manager's  group to auto escape in  --Domain Users group (which is default under Auth Services in XG).

    Thanks,

    Kumar

Reply
  • Hi Aditya,

    Even after reordering the groups as suggested in your post, user's are getting reset to (in my case default user group) --Domain Users. In AD I have created a separate group/OU for Managers and separate group for Users. I suspect that CCA is causing the reset of managers to domain users.

    I have imported group successfully on XG referring https://community.sophos.com/kb/en-us/123158 . Please suggest a permanent solution to stop users under manager's  group to auto escape in  --Domain Users group (which is default under Auth Services in XG).

    Thanks,

    Kumar

Children
No Data