Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Deleted user
0 / 0 points
Next:
badges earned

Your Points Tracker
Challenges
Leaderboard
  • Global
  • Feed

Badge for your thoughts?

You're enrolled in our new beta rewards program. Join our group to get the inside scoop and share your feedback.

Join group
Recognition
Give the gift of kudos
You have 0 kudos available to give
Who do you want to recognize?
Why do you want to recognize them?
Kudos
Great job appreciating your peers!
Check back soon to give more kudos.

Past Kudos Given
No kudos given
You haven't given any kudos yet. Share the love above and you'll see it here.

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Active Directory sync issue Edited

Hi

I've been trying for some days to solve this issues, and got to admit. I need some help.

Now every user in our AD gets synced to Confluence, and that’s not the ideal solution, as admin, consultant etc. is synced too due to the AD structure.

I’ve learned that a solution would be to specify, which users to get synchronized using object filtering and the following should work:

  • (&(objectCategory=Person)(sAMAccountName=*)(memberOf=CN=Confluence Users,OU=Confluence,OU=Security Groups,OU=Groups and ressources,OU=Company,DC=Example,DC=Local))

And it also does, sort of. – 3 users get synced out of nearly 200. All 200 users are members of the group “Confluence Users” in our AD.
Two of the users synced are in same OU, the last one is in his own OU.

Setup as of now:

System:

  • Confleunce version: 6.0.5
  • Build Number: 7103

Server Settings:

  • Directory type: Microsoft AD

LDAP Schema:

  • Base DN: OU=Company, DC=Example, DC=Local
  • Additional User DN: OU=Users
  • Additional Group DN: OU=Confluence,OU=Security Groups,OU=Groups and ressources

User Schema Settings:

  • User Object Filter: (&(objectCategory=Person)(sAMAccountName=*))

Group Schema Settings:

  • Group Object Filter: (&(objectCategory=Group)(cn=confluence*))

 

Steps I’ve done:

  • Created new security groups in AD -> new groups didn't have an effect neither on previously working users.
  • Copied working user -> copied user didn’t get synced.
  • Removed the 3 synced users from “Confluence Users” group, synced and they disappeared as they should. – added them to the group, ran a sync again and the same 3 persons appeared in user directory.
  • Removed random users from “Confluence Users”, ran sync, re-added them to the group, synced again, but that didn’t do anything either.
  • Toggled Enable Incremental Synchronisation on/off - > didn’t make a difference.

 

1 answer

1 accepted

0 votes
Answer accepted
Thomas Deiler Community Leader Apr 23, 2021

Dear @Johan Henriksen ,

first of all I have to point out that you did an excellent job how detailed you described your problem. Many requestores just drop one line (sometimes just a copy of the summary into the body) an expect help.

What you did so far seems to be right. The problem with connecting AD to Confluence/Jira is its, per company, individual configuration.

So I strongly recommend to use an LDAP browser to find the correct User Object Filter. Doing this from within Confluence is pure pain.

Also very helpful is somebody of the AD admins. If well trained, they could bring value.

And last but not least read into the AD/LDAP syntax reference. This is not always intuitive.

So long

Thomas

Hi Thomas

Turned out the LDAP user didn't have access to read memberOf due to permissions in our AD - just wasn't part of the correct AD group which gave the specific access. Rookie mistake.

I'm accepting your answer as the solutions, as the LDAP browser was part of the finding :) 

Thanks

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Confluence

🥓🙅🏻‍♀️ Meet-less May Badge!

Hello Confluence Community!  What if i told you that you could have a healthier life and be 100% meet-less? This month, we're promoting a healthy, balanced work diet with Confluence. (Read m...

747 views 4 26
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you