• Missing "New user" button once I configure AD integration

  • OpenKM has many interesting features, but requires some configuration process to show its full potential.
OpenKM has many interesting features, but requires some configuration process to show its full potential.
Forum rules: Please, before asking something see the documentation wiki or use the search feature of the forum. And remember we don't have a crystal ball or mental readers, so if you post about an issue tell us which OpenKM are you using and also the browser and operating system version. For more info read How to Report Bugs Effectively.
 #48944  by sonnysiah
 
Hi,

Just to confirm if I configured AD integration and it work fine no problem login via AD directory, I found the existing user okmAdmin will be remove and New user button also hidden, I try manually enter the URL /OpenKM/admin/Auth?action=userCreate and I can see user creation screen, I try fill up a test user seem can saved but once url refresh the created user missing again.

I feel that once integrate with AD, there are some security features unable to apply to user like I cannot create new profile to assign to user, this is very useful for most cases.
Attachments
t1.jpg
t1.jpg (79.44 KiB) Viewed 1803 times
 #48948  by jllort
 
Obviously, when you integrate AD you only have read access to the AD ( otherwise you will have a security break ), that's why you are not allowed to add users from openkm to the AD, basically you do not have grants for doing it. You must manage users from your AD.

You can create new profiles an assign to users.
 #48951  by sonnysiah
 
Hi,

Is there a way to "adding" AD user into OpenKM database so that we can further set customize profile into it, we need to "hide" certain option like create folder etc to users? This is useful in production since only certain people allow to create folders only.

Thanks.
 #48966  by jllort
 
If you are not listing users in the User panel, then your AD integration is wrong and should modify until you get users there.

About grants, the AD integration is full, users and roles are binding from AD, that means when you apply a group in the AD, also you are applying in OpenKM too. The roles used in your AD are the same as they are used in OpenKM.

About Us

OpenKM is part of the management software. A management software is a program that facilitates the accomplishment of administrative tasks. OpenKM is a document management system that allows you to manage business content and workflow in a more efficient way. Document managers guarantee data protection by establishing information security for business content.