Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check Permission via AD group - LDAPCP #32

Closed
Albino1006 opened this issue Dec 11, 2017 · 4 comments
Closed

Check Permission via AD group - LDAPCP #32

Albino1006 opened this issue Dec 11, 2017 · 4 comments
Assignees
Labels

Comments

@Albino1006
Copy link

Hello Yvan,

We have encounter an issue in our SharePoint environment using LDAPCP.

Consider a scenario where a user is granted XYZ permission via AD group in SharePoint (and not explicitly using his ID). Now when we do check permission with that user ID, it should show that this user has XYZ permission via that AD group, but it doesn't (it only shows the permission assigned to it via his ID).

This behavior is seen only on sites with custom Identity provider using LDAPCP and not on sites with AD NTLM.

Are we missing something? Awaiting your reply. Thanks.

@Yvand
Copy link
Owner

Yvand commented Dec 11, 2017

Hi @Albino1006
For this to work, it requires that augmentation is enabled and configured in LDAPCP.
Can you confirm if you did so in LDAPCP configuration page?

@Yvand Yvand self-assigned this Dec 11, 2017
@Albino1006
Copy link
Author

Hello @Yvand

We have enabled the augmentation option and selected the claim type from dropdown. But still it doesn't show that the user has XYZ permission via that AD group on checknow in SharePoint permission page.

Is there anything else that can be checked?
Also what does this augmentation option do on enabling it?

Awaiting your reply. Thanks.

@Albino1006
Copy link
Author

Hello @Yvand

We have enabled the augmentation option and selected the claim type from dropdown. But still it doesn't show that the user has XYZ permission via that AD group on checknow in SharePoint permission page.

Is there anything else that can be checked?
Also what does this augmentation option do on enabling it?

Awaiting your reply. Thanks.

@Yvand
Copy link
Owner

Yvand commented Dec 14, 2017

Basically, when you enable augmentation, LDAPCP will generate claims to provide the group membership of trusted users to SharePoint.
Then those role claims will be added to both the SAML token and the external (non-interactive) token of trusted users.

@Yvand Yvand added the question label Jan 31, 2018
@Yvand Yvand closed this as completed Jan 31, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants