2021-09-08 10:02 AM
Hi Guys,
We have RSA Netwitness and we have added Active Directory server so users can login from to the SA using AD credentials. My query is that how it's possible to add individual AD accounts instead of only entire groups? Also, if I add a AD group, I am able to add only one Role ( like admin OR Analyst ) to that group. This mean the only way now is to create different groups for different levels of access or is there any other way ?
2021-09-08 12:27 PM - edited 2021-09-08 12:27 PM
It's only possible to add external AD security groups, not individual user accounts.
But you can certainly assign multiple roles to the external group - simply need to keep adding them to the group within the Admin/Security --> External Group Mapping tab:
2021-09-08 12:27 PM - edited 2021-09-08 12:27 PM
It's only possible to add external AD security groups, not individual user accounts.
But you can certainly assign multiple roles to the external group - simply need to keep adding them to the group within the Admin/Security --> External Group Mapping tab:
2021-09-09 01:19 AM
Thanks for your reply. That was helpful and I'll try that. Once I assign multiple roles to the group then I can then assign individual roles to the user from one of those roles right ?
2021-09-09 02:59 AM
@JoshRandall Once the AD user belonging to the AD group logs in, how do I assign him one of the roles which I have assigned the AD group? When I edit user I cannot see any such option to assign roles to them.
2021-09-09 02:08 PM
You assign permissions to Roles and External Group Mappings, not to individual users. Users with those roles will receive the assigned permissions.