Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
David_Herselman
Advisor
Jump to solution

AD UPN Suffix

We have Identity Awareness configured and working with AD Query, Captive Portal (including Kerberos SSO), Terminal Services MuH and RADIUS for Enterprise WiFi (Packet Fence).

We however have problems with user accounts where their Active Directory UPN Suffix was changed as this then no longer matches the domain in the LDAP Account Unit.

What is the official way to configure additional UPN Suffixes?

 

What we've done so far:

Created additional LDAP Account Units, referencing the same AD servers, credentials and LDAP branch as the one for the AD realm but then unset 'User management' and 'AD Query'.

 

Problem is that RDS (Terminal Services) MuH agent uses Kerberos to identify users and identifies the person as user@upnsuffix2 but then doesn't resolve group memberships.

 

The account is technically party of the main/original LDAP Account Unit, is there no way to configure UPN suffix aliases?

 

adlogconfig a gives an option relating to 'add domain' but I'm unable to locate documentation relating to this...

 

 

Regards

David Herselman

0 Kudos
5 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events