Why are some AD users disabled?

Frank April 15, 2015

For no obvious reason a subset of our AD-users are marked "disabled" in Confluence.
Their group memberships are listed correctly and everything is fine except the fact that they are marked "disabled" and cannot log in.
To be exact: they can log in (password seems to be verified successfully against AD) but they have access to no content whatsoever.

Any ideas what might be the reason and how i can get to the bottom of that issue?

2 answers

1 accepted

0 votes
Answer accepted
Frank April 15, 2015

I found the reason for the strange behavior: the DN that came back from AD is not necesarily unambiguous and at the same time in confluences' AD adapter "naive matching" was enabled - which requires unique DNs.

So i now turned off naive matching and got to know my AD internals a little better wink

Wiki Hard!

0 votes
Simon Kegel //SEIBERT/MEDIA
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
April 15, 2015

Hey Frank,

is there some more info about these users? Do they share some permission the enabled users haven't f.e.?
I could imagine your user limit is just reached. 

Greets
Simon 

Frank April 15, 2015

Hey Simon,

the disabled users do share the same groups and therefore also the same permissions as the not-disabled users - they have some additional groups that the other users don't have - but they are not configured in any way that should interfere/influence confluence.

 

User limit is not reached - i checked that explicitly because it was also one of my firtst thoughts wink License details tells me we have now 72 of 100 users - so that is not the source either.

 

Only difference between the users i could imagine is that they're in a different sub-folder (~= OU) within AD than the rest of the users.

\ domain.local
.|
.\ MyBusiness
..|
..\ Users
...\- OU1 (working users)
...|
...\- OU2 (disabled users)

However I have no deeper knowledge of how this would affect their ability to log in..?

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events