Confluence 4.0 / Windows Server 2008 / Microsoft Active Directory
We have a directory of over 5000 users. What we want is for a user to come to the Confluence application and be able to use it straight away without any administration involvement. So far we have tried Microsoft Active Directory with Read Only with Groups. "Sync fails" and while the user GUID appears correctly in the header the message they get is "Access not permitted" which means that they are not being added to a group. Why?
Tried "Delegated LDAP Integration" which seems to be a better option but still doesn't work.
So while there is a great deal of documentation we are still a bit lost.
1. Do we need to create 'confluence-user' as a group in Active Directory?
2. What is the best LDAP integration option given the requirement of how a user can access the site?
3. What causes the sync to fail?
Any and all help is greatly appreciated.