Version Affected: All
Overview
This article explains how to exclude a specific Organizational Unit (OU) from SecureAuth's Active Directory (AD) lookups, when the Data tab's connection string is set to the root of the domain.
Exclude an OU from SecureAuth's AD Lookups
On the Data tab, the connection string sets the starting OU that SecureAuth searches. If a realm has several top-level OUs, the connection string is usually set to the root of the domain so all of them are reachable — but this means every OU under that root is visible to SecureAuth, including any OU that should be excluded.
The most reliable way to exclude a specific OU is to remove the SecureAuth service account's ability to see it in Active Directory itself, rather than in SecureAuth:
- If Active Directory already has granular permissions configured, remove the service account's Read permission from that OU's access control list (ACL).
- If Active Directory uses the standard model where all Authenticated Users have read access, add an explicit Deny Read permission for the service account on that OU instead.
Special Considerations
Applying Deny permissions in Active Directory requires care — a Deny permission can have broader effects than intended if misapplied. Consult your Active Directory administrator before making this change.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.