Skip to Content

Active Directory (AD) User Group Creation and Mapping

 

How to Create an Active Directory (AD) User Group and Assign Users?


Overview: This article explains how to create a new Active Directory (AD) user group, add users to that group, and map it inside the Ezeelogin Gateway Server.


Step 1: Log in to your Windows Server where Active Directory is installed.

Step 2: Open Server Manager → Tools → Active Directory Administrative Center

Step 3: Navigate to the OU (Organizational Unit) where you want to create the group and select New → Group

 

Step 4: Provide Group name and click ok

Step 5: Right click the username and select properties

Step 6: Scroll down to the 'Member Of' section, click Add, enter the group name, and then click OK.

Step 7: Create the same user group in Ezeelogin GUI under Users ->User Groups

Note:  Make sure to use the exact group name in Ezeelogin as in active directrory (case sensitive) to auto import user to the same user group.

Note: 

1. If users from the OIDC provider need to be auto-created in the corresponding group from OIDC to the same group in Ezeelogin, the admin user must set the default user group to None. If the same group is not present in Ezeelogin, the user will not be auto-created.

2. If the default user group is set to any group other than None, then all users from the OIDC provider will be auto-created in that same group.

This feature is available from Ezeelogin version 7.46.0. Refer article to upgrade Ezeelogin to the latest version.

Note: 

User attributes (such as groups and other mapped fields) are automatically updated in the Ezeelogin GUI when a user authenticates again. If any attribute of an existing LDAP user is changed in the identity provider after the user has already logged in, the change will appear in the GUI only after the user logs out and logs back in.

For example, if a user is moved to a different group in the LDAP provider (such as Windows Active Directory), the updated group will be shown in the Ezeelogin GUI after the user logs in again.

This feature is available from Ezeelogin version 7.46.0. Refer article to upgrade Ezeelogin to the latest version.

Step 8: Navigate to Users -> LDAP and select the LDAP users and import them to Ezeelogin.

Step 9: Verify that the imported LDAP users appear in the Users tab under the correct user group.

Note: After importing the users to Ezeelogin, log in with the user and set up a security code for the user under Account -> Password -> New Security Code.


Related Articles:

Configure Ezeelogin to authenticate using Windows_AD(Pam-Ldap) in Ubuntu

How do I configure Ezeelogin to authenticate using Windows_AD(Pam-LDAP) in CentOS

How do I configure Ezeelogin to authenticate using OpenLdap(Pam-Ldap) in CentOS

How to configure Ezeelogin to authenticate using Open_Ldap(Pam-Ldap) in Ubuntu

How do I configure Ezeelogin to authenticate using OpenLdap or Window AD server?

Assigning user groups for LDAP users?

Can we map the existing user group in LDAP to ezeelogin as the ezeelogin user group?

AdAD as LDAP with non-administrator user

Configure a replica LDAP/AD Server