0 votes

When configuring web page - under "Object Selection" - you can only choose 1 location (OU) when you select "Allow selecting only AD objects located under" - is there a way to have multiple OUs instead - perhaps using a LDAP filter?

by (20 points)

1 Answer

0 votes
by (210k points)

Hello,

Unfortunately, there is no possibility to select multiple OUs/containers or use an LDAP filter in a similar way. The thing is that wildcards are not allowed for DN syntax properties (e.g. distinguished name) in LDAP filters. The restriction comes from Active Directory itself, not Adaxes. If the objects that you need to be available for selection have specific property values, then using an LDAP filter will work just fine. For example, in case of the Modify User action, the following LDAP filter can be used to allow selecting only users whose department is Sales or IT Staff:

(&(sAMAccountType=805306368)(|(department=Sales)(department=IT Staff)))

Related questions

0 votes
1 answer

Hello, I want service desk to be able to select from the web interface only groups that are specified in a Business Unit. it is possible to do it (Adaxes 2009.1)? Thanks you.

asked Sep 2, 2020 by tentaal (1.1k points)
0 votes
1 answer

Hello We are using the Computer Manager security role and have given access to this group of staff to a web console, what I can't get working is getting it to display the ... else like OS, service pack, role are displaying OK. Can you help please? Thank you.

asked Feb 4, 2015 by CBurn (700 points)
0 votes
1 answer

My Help Desk users can unlock accounts one at a time under user management, Unlock Account. However, under the "Locked out Users" on the Home Page, there is no option to select multiple users to unlock- the check boxs are not visible.

asked Mar 12, 2020 by msylvester (60 points)
0 votes
1 answer

We're finding more and more that we would like the ability to configure a home page action that can target objects from multiple OUs. In other words, under "Object Selection ... LDAP filter but was hoping you all might know a way around this. Thanks in advance

asked Oct 16, 2012 by VTPatsFan (610 points)
0 votes
1 answer

I have setup a form to allow HR to edit some details on AD accounts. Currently the scope is limted to only AD object under one pre-chosen OU. The other option is an ldap filter. How can I allow this action to display user accounts from two seperate OU

asked Nov 18, 2019 by ice-dog (170 points)
2,599 questions
2,338 answers
6,212 comments
848,568 users