cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
tcilmo
Engaged Sweeper II
What is the process for adding an Active Directory User Group as a Lansweeper user? Does Lansweeper have to SCAN Active Directory to obtain a all the user and user groups first? -Tony
14 REPLIES 14
Karel_DS
Champion Sweeper III
You could technically delete scanned AD users by running a database script. Users only get (re)scanned if their ADSI path is mentioned on the scanning page. But if you really don't like them showing up in your widgets this link might help: http://www.lansweeper.com/Forum/yaf_postst10618_I-need-to-mass-delete-Active-Directory-Users.aspx#po.... We advise not to delete AD users that have been made help desk users. If you want user data to be updated when scanned then make sure the option Refresh Active Directory user details is enabled in the User cleanup section of the Configuration -> Server Options page. You can lock certain user data for specific users by editing a user either on a user's web page, on a ticket, or on the Configuration -> User Access & Roles page.

You can already download the next update using this link: http://www.lansweeper.com/public/6022/LansweeperSetup.exe.
tcilmo
Engaged Sweeper II
I beleive I have the Active Directory user scanning down, but I accidentally pointed to the wrong location when entering an ADSI path. I corrected the ADSI path, but how do I remove all of the users that were scanned that should not have been? Will the accounts correct them selfs once the scan completes again since it is now pointed to the correct ADSI Location?

Glad to hear we will be able to assign permissions using Active Directory groups! Any expected ETA on the next update?

P.S. I can't upload a screen shot from my workstation. I can only link to one picture on the web which is not helpful to helpful. lol

Thanks for all your help so far!


-Tony
Karel_DS
Champion Sweeper III
When you scan AD users all of its related groups will be scanned as well. You can view these groups near the bottom of the user's webpage, which you can go to either by using the search option on top or clicking on the user's name anywhere on the website. You can see other (scanned) members of this group by clicking on the group name. You can view all scanned users using the 'Active Directory Users OU' widget.

There is currently no possibility to immediately add all users of a specific AD group to the table with helpdesk users. There is also no possibility to 'make an AD group a single LS user'. However our next update will allow scanned AD groups to be used to implement user permissions, similar to versions before 6.0.
tcilmo
Engaged Sweeper II
I was able to scan the "USERS" folder in Active Directory and the scanned users are now showing up when I attempt to add a domain user. Does Lansweeper scan AD groups? I would like to be able to make an AD group a single Lansweeper user. Is this possible? I have been trying to use a scanning target to hit a specific OU in Active Directory to collect the groups within it, but have been unsuccessful.

-Tony
Karel_DS
Champion Sweeper III
Yes you'll have to add and perform an 'Active directory user/group path' scan (Scanning -> Scanning Targets). After the scan you will be able to add the users either by going to 'Configuration -> User Access & Roles' and pressing the 'Add AD user' button (drag or Ctrl + click to select multiple), or making a ticket and selecting the user (a help desk user will then be created using its AD data).

The help desk users table will also be populated when new users log in on the web console. Their data from AD will be used if it got scanned. If their AD group gets scanned after they logged in then they will get immediately linked to their AD account.