How To: Exclude an Organizational Unit from SecureAuth's AD Lookups

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    This article explains how to exclude a specific Organizational Unit (OU) from SecureAuth's Active Directory (AD) lookups, when the Data tab's connection string is set to the root of the domain.

     

    Exclude an OU from SecureAuth's AD Lookups

    On the Data tab, the connection string sets the starting OU that SecureAuth searches. If a realm has several top-level OUs, the connection string is usually set to the root of the domain so all of them are reachable — but this means every OU under that root is visible to SecureAuth, including any OU that should be excluded.

    The most reliable way to exclude a specific OU is to remove the SecureAuth service account's ability to see it in Active Directory itself, rather than in SecureAuth:

    • If Active Directory already has granular permissions configured, remove the service account's Read permission from that OU's access control list (ACL).
    • If Active Directory uses the standard model where all Authenticated Users have read access, add an explicit Deny Read permission for the service account on that OU instead.


     

    Special Considerations

    Applying Deny permissions in Active Directory requires care — a Deny permission can have broader effects than intended if misapplied. Consult your Active Directory administrator before making this change.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.