<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0">

    <channel>

        <title>Cyn.in Active Directory Integration</title>
        <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration</link>
        <description>A stepwise walkthrough for setting up integrated authentication with MSAD for authentication, group assignment and user schema field synchronization.</description>

        <generator>basesyndication</generator>

        <image>
            <title>Cyn.in Active Directory Integration</title>
            <url>http://www.cynapse.com/community/logo.jpg</url>
            <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration</link>
        </image>

        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1366042394</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1366042394</link>
                <description>Hello,&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;Following this tutorial, im still facing some trouble with user's email address import from the AD. Basically, cyn.in imports the CN and groups but no email address :(&lt;br /&gt;It's a bit strange cause under Zope, when i search for an user info, i do have his email address, displayName...etc&lt;br /&gt;I put everything i could under /cynin/portal_metadata/properties (CN,mail...etc)&lt;br /&gt;What could be wrong?</description>
                <author>greg</author>


                <pubDate>Mon, 15 Apr 2013 16:13:21 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title>Cyn.in Active Directory Integration</title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration</link>
                <description>
&lt;h2&gt;Get to ZMI Screen for your site.&amp;nbsp;&lt;/h2&gt;
&lt;p&gt;Login with admin user (password: Whatever you changed it to, from the default of "secret") at &lt;strong&gt;http://&amp;lt;siteURL OR IP address&amp;gt;:8080/manage&lt;/strong&gt; to get ZMI screen&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup001" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup001.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup001.jpg/image_large" alt="msadldapsetup001" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Open up your site (cynin link) and click portal_quickinstaller&lt;/h2&gt;
&lt;p&gt;&lt;a title="msadldapsetup002" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup002.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup002.jpg/image_large" alt="msadldapsetup002" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Install LDAP Support&lt;/h2&gt;
&lt;p&gt;Check the product shown and hit the Install button&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup003" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup003.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup003.jpg/image_large" alt="msadldapsetup003" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Go to /cynin/acl_users and add ACL plugin&lt;/h2&gt;
&lt;p&gt;For Microsoft Active Directory, this &lt;em&gt;&lt;strong&gt;must be&lt;/strong&gt;&lt;/em&gt; : Plone Active Directory plugin, for other services, Plone LDAP plugin would be first choice&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup004" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup004.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup004.jpg/image_large" alt="msadldapsetup004" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Fill in the details for the AD connection...&lt;/h2&gt;
&lt;p&gt;This is the crucial step, and must be done right, because without successful connection, the plugin will not install and all you'll get is an Error screen. If you &lt;em&gt;do&lt;/em&gt; get an error screen, hit Back in your browser, and change what is needed to fix, and try again.&lt;/p&gt;
&lt;p&gt;More details follow in further screenshots.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup005" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup005.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup005.jpg/image_large" alt="msadldapsetup005" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Get details from your AD&lt;br /&gt;&lt;/h2&gt;
&lt;p&gt;For doing this with MSAD specifically, I recommend the &lt;a class="external-link" href="http://technet.microsoft.com/en-us/sysinternals/bb963907.aspx"&gt;SysInternals tool, AD Explorer&lt;/a&gt;. You need to use a tool only to determine the values of your DNs for the AD hookup. If you're well versed with your configuration, then just follow along and fill in appropriate values.&lt;/p&gt;
&lt;p&gt;So install AD Explorer, open it up, connect to your Active Directory, and go to the DC, navigate to the place where you're storing User data. This is typically (at least in the out-of-box setup), going to be the one highlighted in the screenshot.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup006" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup006.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup006.jpg/image_large" alt="msadldapsetup006" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Pick up the base DN and paste&lt;/h2&gt;
&lt;p&gt;The default AD setup has users and groups in the same DN, Users, so do a right-click on the Folder, and copy the value of Distinguished Name, and paste it into both, the Users Base DN and the Groups Base DN fields. Adjust as required for your own setup, if different.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup007" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup007.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup007.jpg/image_large" alt="msadldapsetup007" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Pick up the DN of the Administrator user and paste&lt;br /&gt;&lt;/h2&gt;
&lt;p&gt;The Plone AD plugin will use &lt;em&gt;this&lt;/em&gt; user to connect to your AD, so if you're not particular about it, the Administrator user will do (right click-&amp;gt;properties on the Admnistrator user), else substitute any&lt;em&gt; &lt;/em&gt;user's DN as appropriate, just make sure at least Read access to the Base DN that you're selecting is available.&lt;/p&gt;
&lt;p&gt;Paste the DN into... you guessed it, the Manager DN field. :)&lt;/p&gt;
&amp;nbsp;
&lt;p&gt;&lt;a title="msadldapsetup008" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup008.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup008.jpg/image_large" alt="msadldapsetup008" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Fill in the remaining fields&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;Fill in the password for the Admin user.&lt;br /&gt;
&lt;/li&gt;&lt;li&gt;Fill in the hostname and port of the AD server in the LDAP Server:port field. The format of this &lt;em&gt;must be&lt;/em&gt; either IPAddress:port (as shown), or hostname:port, as per your needs.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Check on Read Only unless you want users to be able to modify their AD profile through their Cyn.in profile.&lt;/li&gt;&lt;li&gt;Change the default user roles from Anonymous, Member to just Member&lt;/li&gt;&lt;li&gt;Fill in an ID and a Title. Whatever you want in this, it doesn't really matter, just as long as you remember it.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;a title="msadldapsetup009" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup009.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup009.jpg/image_large" alt="msadldapsetup009" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;... And hit Save&lt;/h2&gt;
&lt;p&gt;Now depending on validation of the info you filled in, you'll either get the screen shown below, with your newly added item showing in the list, or you'll get an error, if the connection to your AD failed. Diagnose and adjust accordingly, if so by hitting back in your browser and changing what's necessary. Passing this step is &lt;em&gt;crucial&lt;/em&gt; for the integration to work.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup010" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup010.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup010.jpg/image_large" alt="msadldapsetup010" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Turn on all the plugin's methods, hit Update&lt;br /&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a title="msadldapsetup011" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup011.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup011.jpg/image_large" alt="msadldapsetup011" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Click the Properties plugin and move it higher in priority&lt;/h2&gt;
&lt;p&gt;Select the AD plugin&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup012" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup012.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup012.jpg/image_large" alt="msadldapsetup012" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; and click the Up arrow to move it up.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup013" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup013.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup013.jpg/image_large" alt="msadldapsetup013" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Fix the incorrect Group ID Attribute in Properties Tab&lt;br /&gt;&lt;/h2&gt;
&lt;p&gt;Change from groupid_attr = ObjectGUID to...&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup014" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup014.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup014.jpg/image_large" alt="msadldapsetup014" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;... to groupid_attr = sAMAccountName and hit Save.&lt;/p&gt;
&lt;p&gt;Yes, the case of the value is important, you have to type it &lt;em&gt;exactly as shown&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup015" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup015.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup015.jpg/image_large" alt="msadldapsetup015" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Open the Contents tab&lt;/h2&gt;
&lt;p&gt;...and then open up the nested acl_users object.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup016" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup016.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup016.jpg/image_large" alt="msadldapsetup016" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Fix the User Object Classes&lt;/h2&gt;
&lt;p&gt;Change from pilotPerson, uidObject to...&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup017" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup017.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup017.jpg/image_large" alt="msadldapsetup017" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;..... to organizationalPerson, as shown. Again, CaSe is important.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup018" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup018.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup018.jpg/image_large" alt="msadldapsetup018" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Check the Groups tab&lt;/h2&gt;
&lt;p&gt;You should see all the groups in your AD showing up here, now. Verify that all looks ok, don't change anything.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup019" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup019.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup019.jpg/image_large" alt="msadldapsetup019" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Verify User lookup&lt;/h2&gt;
&lt;p&gt;Click the Users tab, fill in a known value and choose the appropriate field, and hit Search.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup020" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup020.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup020.jpg/image_large" alt="msadldapsetup020" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Verify the Search Results&lt;br /&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a title="msadldapsetup021" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup021.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup021.jpg/image_large" alt="msadldapsetup021" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Click a result and ensure correct Group assignment&lt;/h2&gt;
&lt;p&gt;The user should have appropriate Groups checked as per "belongs to" relationship.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup022" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup022.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup022.jpg/image_large" alt="msadldapsetup022" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Login should now be working with AD :)&lt;br /&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a title="msadldapsetup023" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup023.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup023.jpg/image_large" alt="msadldapsetup023" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;But you still have to do Schema mapping...&lt;/h2&gt;
&lt;p&gt;The fullname of the user, the email address is not being mapped to the user yet. You need to map this up properly so that things like notification emails, etc. work properly. Read on...&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup024" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup024.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup024.jpg/image_large" alt="msadldapsetup024" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Go to LDAP Schema tab...&lt;/h2&gt;
Add displayName as FullName
&lt;p&gt;&lt;a title="msadldapsetup025" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup025.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup025.jpg/image_large" alt="msadldapsetup025" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Add mail as email&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup026" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup026.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup026.jpg/image_large" alt="msadldapsetup026" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Refer to /cynin/portal_metadata and map other fields&lt;br /&gt;&lt;/h2&gt;
&lt;p&gt;Navigate out to /cynin and then to portal_metadata object. Here, you'll see the fields that Cyn.in currently stores against all users.&lt;/p&gt;
&lt;div class="warning"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Some fields are not wired up yet, use this screen for reference only.&lt;/div&gt;
&lt;p&gt;The idea is that you can map things like phone numbers, job titles (designation), etc., by matching these fields against the ones stored and in use, in your AD. To add a new mapping, see the name here, compare it with your AD field's name and add a new mapping in LDAP schema screen, as shown for displayName and mail. The rest of the fields are left up to you as per your requirements and usage.&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;If you &lt;em&gt;don't&lt;/em&gt; map a field, it won't get filled automatically, but your users will be able to use it normally from their Cyn.in edit profile&lt;br /&gt;&lt;/li&gt;&lt;li&gt;If you &lt;em&gt;do&lt;/em&gt; map a field, and your AD connection is set to Read Only, then users will not be able to edit it&lt;br /&gt;&lt;/li&gt;&lt;li&gt;If you &lt;em&gt;do &lt;/em&gt;map a field, and you AD connection is not set to Read Only, then changes users will make, &lt;em&gt;will &lt;/em&gt;make it back to your AD, if the username/password combination you put in the Manager DN field has write permssions&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;a title="msadldapsetup027" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup027.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup027.jpg/image_large" alt="msadldapsetup027" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Clear Cache and revisit&lt;/h2&gt;
&lt;p&gt;If you, like me, wanted to login first to see if it works, then you get to visit the Caches tab to purge all caches, after you do the schema mapping.&lt;/p&gt;
&lt;p&gt;Logins are cached as per the setting in the Caches tab, so that your AD is not looked up constantly. Tweak here only if necessary.&lt;/p&gt;
Once you map up the schema as per above, your People Directory will come pre-populated with the users from your AD, as shown. If you're setting up a complex Space structure, do note that you &lt;em&gt;can&lt;/em&gt;
&lt;p&gt; map groups from AD to local roles on the Sharing tab of a Space - and it should work fine.&lt;/p&gt;
&lt;p&gt;&lt;a title="msadldapsetup028" class="internal-link" href="/community/home/cyn.in-users/msadldapsetup028.jpg"&gt;&lt;img class="image-inline" src="/community/home/cyn.in-users/msadldapsetup028.jpg/image_large" alt="msadldapsetup028" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;So set your Cyn.in's up, let's see if you can get it to work properly. :)&lt;/p&gt;
&lt;p&gt;Let us know if you have any ideas, suggestions about this or if you get stuck in a problem with the AD integration, just post up a new discussion with the details.&lt;/p&gt;
</description>
                <author>Dhiraj Gupta</author>

                
                    <category>active directory</category>
                
                
                    <category>documentation</category>
                
                
                    <category>authentication</category>
                
                
                    <category>ldap</category>
                
                
                    <category>msad</category>
                

                <pubDate>Mon, 15 Apr 2013 16:13:18 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1356339444</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1356339444</link>
                <description>Our AD structure is defined as follows&lt;br /&gt;domain.com&lt;br /&gt;&amp;nbsp;&amp;gt; Location1.OU&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; Computers&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; Users&lt;br /&gt;&amp;gt; Location2.OU&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; Computers&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; Users&lt;br /&gt;.....&lt;br /&gt;&amp;gt; LocationN.OU&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; Computers&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; Users&lt;br /&gt;&lt;br /&gt;I can not use the root dn as it has sensitive information. Is there a way to define multiple Location OUs to grab all users?</description>
                <author>Abhinandan Sankolli</author>


                <pubDate>Mon, 24 Dec 2012 08:57:28 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1354171410</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1354171410</link>
                <description>Is it possible at all to filter groups?&lt;br /&gt;Our AD has all our security groups in one OU, but I only need a few of them for this and the rest just cause mess.</description>
                <author>Jason Weber</author>


                <pubDate>Thu, 29 Nov 2012 06:43:31 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1354171407</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1354171407</link>
                <description>Is it possible at all to filter groups?&lt;br /&gt;Our AD has all our security groups in one OU, but I only need a few of them for this and the rest just cause mess.</description>
                <author>Jason Weber</author>


                <pubDate>Thu, 29 Nov 2012 06:43:27 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1354171388</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1354171388</link>
                <description>Is it possible at all to filter groups?&lt;br /&gt;Our AD has all our security groups in one OU, but I only need a few of them for this and the rest just cause mess.</description>
                <author>Jason Weber</author>


                <pubDate>Thu, 29 Nov 2012 06:43:20 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1353016551</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1353016551</link>
                <description>tgelhardt, how did you fix the problem? I have having the same issue.</description>
                <author>David Overton</author>


                <pubDate>Thu, 15 Nov 2012 21:55:55 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1349379686</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1349379686</link>
                <description>Fixed!</description>
                <author>Tim Gelhardt</author>


                <pubDate>Thu, 04 Oct 2012 19:41:26 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1349213502</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1349213502</link>
                <description>I followed each step to the point. I have reached the end of the guide and my &amp;quot;People Directory&amp;quot; is still blank. I'm able to log in using AD credentials. I have go back through step by step and everything appears to be set correctly. Please help!</description>
                <author>Tim Gelhardt</author>


                <pubDate>Tue, 02 Oct 2012 21:31:47 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1345881429</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1345881429</link>
                <description>Interesting post. I have been wondering about this issue,so thanks for posting. &lt;br /&gt;&amp;lt;a href=&amp;quot;&lt;a href="http://exampost.net/&amp;quot;&amp;gt;exampost&amp;lt;/a&amp;gt;&amp;quot;thanks&amp;quot;" rel="nofollow"&gt;http://exampost.net/[&amp;hellip;]/a&amp;gt;&amp;quot;thanks&amp;quot;&lt;/a&gt;</description>
                <author>amit gupta</author>


                <pubDate>Sat, 25 Aug 2012 07:57:10 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1341500627</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1341500627</link>
                <description>Hi there.&lt;br /&gt;I am testin the product, but when I go to address:8080/manage asks for a passwd. I tried &amp;quot;siteadmin&amp;quot;/&amp;quot;secret&amp;quot; and tried to create a new user inside cynin to give &amp;quot;admin rights&amp;quot; to him.&lt;br /&gt;None user can auth in this screen. What I have to do? Any sugestion?&lt;br /&gt;&lt;br /&gt;Thanks for help.&lt;br /&gt;</description>
                <author>Daniel Godoy</author>


                <pubDate>Thu, 05 Jul 2012 15:03:54 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1334229152</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1334229152</link>
                <description>When I wan't to change something in LDAPUserFolder at  /ipo/acl_users/corproot.net/acl_users I get this error:&lt;br /&gt;&lt;br /&gt;Traceback (innermost last):&lt;br /&gt;&amp;nbsp;&amp;nbsp;Module ZPublisher.Publish, line 119, in publish&lt;br /&gt;&amp;nbsp;&amp;nbsp;Module ZPublisher.mapply, line 88, in mapply&lt;br /&gt;&amp;nbsp;&amp;nbsp;Module ZPublisher.Publish, line 42, in call_object&lt;br /&gt;&amp;nbsp;&amp;nbsp;Module Products.LDAPUserFolder.LDAPUserFolder, line 464, in manage_edit&lt;br /&gt;&amp;nbsp;&amp;nbsp;Module Products.LDAPUserFolder.LDAPDelegate, line 262, in connect&lt;br /&gt;INVALID_CREDENTIALS: {'info': '80090308: LdapErr: DSID-0C090334, comment: AcceptSecurityContext error, data 52e, vece', 'desc': 'Invalid credentials'}&lt;br /&gt;&lt;br /&gt;Need help!!!!!</description>
                <author>Patrick Mischler</author>


                <pubDate>Thu, 12 Apr 2012 11:12:34 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1326809582</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1326809582</link>
                <description>I am having an issue with my MS AD groups.  After following the directions I am able to query and display the AD users, but get an error when trying to show the groups (I think I have too many?).  In my AD, the groups and users are in the same container (CN=USERS,DN=CORP,DN=MyCompany,DN=NET)&lt;br /&gt;Has anybody had a similar problem.  Unfortunately, after messing around with it, I completed borked my install and couldn't even login anymore to get the error details to share, so I did a reinstall.  Before I go and start mucking around again, I was looking to see if anybody had a similar experience and how they might have gotten past it.  Maybe using the generic LDAP connection instead of the specific AD.&lt;br /&gt;&lt;br /&gt;Thanks in advance.</description>
                <author>Darren Handler</author>


                <pubDate>Tue, 17 Jan 2012 14:13:05 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1319226919</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1319226919</link>
                <description>Does anyone know why a user fat finger their password only once and his/her account would be locked out on the first failed attempt when we integrate Cyn.in with AD?  Is there a setting to avoid this? Our AD is setup to lock out the account after 3 failed attempts.  </description>
                <author>Huy Bonds</author>


                <pubDate>Fri, 21 Oct 2011 19:55:21 +0000</pubDate>

                
            </item>
        
        
            <item>
                <title></title>
                <guid>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1317288829</guid>
                <link>http://www.cynapse.com/community/home/cyn.in-users/microsoft-active-directory-services-integration/view/#1317288829</link>
                <description>Great write up of the AD install, the &amp;quot;Additional user search filter&amp;quot; field : (&amp;amp;(objectCategory=person)(objectClass=user)) filtered out all the unwanted computer accounts just leaving the users.</description>
                <author>Peter Carr</author>


                <pubDate>Thu, 29 Sep 2011 09:33:51 +0000</pubDate>

                
            </item>
        

    </channel>
</rss>
