• ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
The HP Community is where owners of HP products, like you, volunteer to help each other find solutions.
HP Recommended

We are busy installing a CMA4000 and RMX1500. I configured the CMA to Integrate into our AD with LDAP. I need to add a specific AAD Group to the CMA as only people in this group should be able to use CMA Desktop. But if I try to Import a group I get an error that it can't find any groups. As soon as I insert the BaseDN it blocks AD Authentication. The BaseDN should be: OU=Groups,OU=Johannesburg,DC=toyota,DC=co,DC=za and the group name is CMA Desktop JHB. Any Ideas?

4 REPLIES 4
HP Recommended

Wessel,

 

The Base DN is used for every LDAP/AD query in the CMA. This tells the CMA where the stating point to start searching within LDAP/AD. This will limit the search to only users and groups below the base dn. Typically the base dn is used to the domain level in order to restrict the ldap search to a particular domain in a group of domains.

 

In your case, if you want to restrict users for CMAD access, then you need to add an exclusion filter. By adding a exclusion filter and changing the syntax a bit, you will make it an inclusion filter. This states if you are in this group, then you have access. I have attached a quick guide to help you understand this process.

 

btw - make sure you are using Universal groups which are the only groups supported ont he CMA. Universal groups get indexed by the global catalog servers and makes it easier to search across multiple domains.

 

S.

HP Recommended

Thanks for the assistance, I changed the group to be a Universal group and I can now see it in CMA. I've put in the exclusion as you sugessted but any user on AD can still log into CMA Desktop. Any Ideas? Only Users in the CMADJHB group should be able to use the Desktop client. In the screen shot I'm showing the filter.

HP Recommended

It looks like you have everything setup correctly. The filter basically tells the CMA to only allow any user in the CMADJHB group access.

 

1) Make sure the CMADJHB groups is also a Universal group.

2) Try rebooting the CMA

3) Can users outside this group log into the CMA?

4) You may need to contact support to get a deeper understanding of this issue, may be a bug.

 

S.

 

 

HP Recommended

Interesting reading, I have exactly the same issue. I have CMA 6.01with Base DN setting (tried with and without this) and ! exclusion filter describing to groups and this has passed the built in syntax check.

 

It all looks simple enough and the logic is sound, but it just doesn't work in that any user can get DMC-D and then login. This isn't an issue for me yet, but its not doing what it should.

 

as you say.... may be a bug.

 

I shall monitor this post, thanks

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.