cancel
Showing results for 
Search instead for 
Did you mean: 

How to configure UME to Use LDAP groups from MS Active Directory

stefan_kulcsar
Explorer
0 Kudos

Hi experts,

i want to implement the following scenario:

If a user wants to have access to SAP Netweaver SA Java System this user has to be a member of a ActiveDirectory group to get this access.

Is this possible? Without doing anything on SAP NW AS Java Identity Management side?

I already configured to get access to AD according (http://help.sap.com/saphelp_nw73ehp1/helpdata/en/12/7678123c96814bada2c8632d825443/content.htm?frame...) in Identity Management of AS Java but if i want to search for a group i only see OU's but not the Active Directory groups.

If somone knows how to configure please let me know.

Thanks in advance.

--

Stefan

Accepted Solutions (1)

Accepted Solutions (1)

stefan_kulcsar
Explorer
0 Kudos

i found the mistake i configure deep hirarchy, if i use flat one (Microsoft ADS (Flat Hierarchy) + Database) everything ist the way ist should.

Thanks.

Answers (1)

Answers (1)

Former Member
0 Kudos

Yes, you just link the respective portal permissions to the AD group. Usually you would use portal roles and link them to respective AD groups. You can then assign permissions to portal roles. If you are not seeing the AD groups it might be because you are using the wrong user data source configuration, you are using the wrong group path, the service user has insufficient authorizations or your AD is configured in an unsupported way.

stefan_kulcsar
Explorer
0 Kudos

as i mentioned i can only search from AD the objects with objectClass organizationalUnit but i want to serch for  objectClass group.

The user for querying LDAP works fine with JXplorer (LDAP browser).

Former Member
0 Kudos

The UME configuration can be adapted, see the attached SAP note for details.

https://service.sap.com/sap/support/notes/1357476