Not able to configure LDAP group lookup

Hi, I've followed https://confluence.atlassian.com/display/JIRA/Connecting+to+an+LDAP+Directory to configure LDAP for my evaluation JIRA. At section Membership Schema Settings it says that there should be two checkboxes to decide whether groups are retrieved from the user (memberOf) or looking up the group and then users (member).

My problem is that only one checkbox is there. Also, if I check LDAP configuration, it seems that both checks are false.

What's happening is that ALL my LDAP users are being synchronized into JIRA, exceeding by far number of licenses.

5 answers

1 accepted

i see no problem here, should work this way
but as i already comment
1) additional group dn only for narrow search of groups within your directory, for narrow user search better add userfilter to corresponding field ( see screenshot )


2) AFAIK doesn't matter how many users jira synced from LDAP only members of "jira-users" group ( group giving access to jira ) are counted to licence

We have solved it adding a new attribute for each user in LDAP, so that filtering works. Thanks for your help!

can you please add a screenshot?

i have 2 fields and one checkbox to choose which field will be used

and it's working fine this way

yes, same configuration is shown in my case. The problem is that although the checkbox is unselected (as yours), when I click on "Save & Test", the test is failing because it's ignoring the unselected "use the user membership attribute". My LDAP has not configured the "memberOf", but "member" for groups.

My configuration also tries to restrict sync'ed users to those belonging to group "staff", so "Additional Group DN" is configured to "cn=staff,ou=Group". But all users are being sync'ed.

i think you are made some errors in config.
can you please post screenshot of config ( you can erase secure-related part ) for better undestand where is the problem

Please find my config.

additional group dn only for narrow group search within your directory
for narrow user search-sync better add userfilter to field

Suggest an answer

Log in or Sign up to answer
Atlassian Community Anniversary

Happy Anniversary, Atlassian Community!

This community is celebrating its one-year anniversary and Atlassian co-founder Mike Cannon-Brookes has all the feels.

Read more
Community showcase
Julia Dillon
Posted Tuesday in Jira

Tell us how your team runs on Jira!

Hey Atlassian Community! Today we are launching a bunch of customer stories about the amazing work teams, like Dropbox and Twilio, are doing with Jira. You can check out the stories here. The thi...

240 views 1 18
Join discussion

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you