Quantcast
Channel: Forefront Edge Security – DirectAccess, UAG and IAG フォーラム
Viewing all articles
Browse latest Browse all 1485

New to UAG - Can we check user group membership (OU) from AD to restrict/allow when logging in?

$
0
0

Hello,

We are new to UAG and trying to get a handle on things. 

We have a situation where we need to "restrict" 4 subdomains which are only accessible by users who are members of their OU group in AD.

For example:

  1. we have 4 subdomains called group1.oursite.com, group2.oursite.com,  group3.oursite.com,  group4.oursite.com.
  2. Users will have to either have to be in one of the groups in AD called group1, group2, group3, and group4.
  3. How do we go about in setting up a UAG login form where when a user logs in, it checks to see which AD group they belong in and then redirects (and secures them) them to their subdomain? This way, when another user who belongs to another group, won't be able to access the subdomains they don't belong in and will be logged out.

Login example:

  1. User jsmith belongs in AD group, group3 and has access to group3.oursite.com
  2. He logs in and is redirected to group3.oursite.com automatically.
  3. Then he realizes that he wants to try and enter the url of  "group1.oursite.com" manually in his browser to see what he can access and anything under that subdomain. Because he does not belong in the AD group of "group1", he will be automatically restricted from accessing group1.oursite.com or is forced to login to that site.

Can this be done and if so, how would we do it?

Thanks

 


Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>