Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Group Authentication

A user starting an import AD groups can participate in two groups at the same time?

I tried this but in configure - Authentication - Group it appears only in 1.

 

Can you help me?

 

Sorry, I am Brazilian and I used the translator to post this question.


Maviael Nascimento


This thread was automatically locked due to age.
  • Maviel,

    XG uses Tight integration , the Username is fetched from the AD along  with its Group association, So if you have imported the Group from AD then it would be assigned to that Group only but Group association must be set primarily on AD server.  Unless the Group is not imported then it would set to Open Group by default .  Also if you create a Group on XG itself and manage to assign a user to be a member of the Group then also it would revert back after an authentication attempt. 

    This is the behaviour on XG.

    Thanks


  • Ok, it was imported from AD, but he can participate in two groups, because I have rules in different groups of users and the same user can this into 2 groups

     

    Obrigado

  • Hi Maviael,

    According to the AD architecture, when the User resides in the Primary group, it's group information will not be shared with XG hence, you need to create the User in a separate group which is not a Primary group for AD. Another behavior is that AD follows a TOP-DOWN approach, which means that when the User resides in two groups in AD, AD will authenticate the user from the group that is on TOP. Hence, the group association information for the User which will be shared by AD to XG only has the information of one group that is on TOP.

    Thanks