Connecting Domain User

Foresight Analytics Platform uses information from domain directory service or global directory to work with domain security subjects. A domain user can be connected if the following supported DBMS are used: PostgreSQL, Oracle, Microsoft SQL Server.

Domain users can be connected by the users who have the Changing User Permissions, Distributing Roles, Changing Policy and the Creating and Deleting Users privileges. When roles of the information security administrator and the application administrator are separated, only the application administrator can connect domain users.

TIP. Before connecting domain users it is recommended to check if LDAP settings are identical in the settings.xml files located in different environments.

To connect a domain user in the Users section:

  1. Select the Add Domain User item in the drop-down menu of the User button on the toolbar. After executing the operation the Search Users and Groups dialog box opens:

  1. Set the parameters:

  2. Click the Find button. After executing the operation the domain users, whose names satisfy search conditions, will be displayed.

  3. Select one or several found users while holding down the CTRL key.

  4. Click the Add button.

After executing the operations the Create Accounts dialog box opens:

Create a user on DB server

Grant rights on DBMS level

The Apply in All Similar Cases checkbox is selected by default, and the selected actions will be executed for all domain users without additional requests.

NOTE. If domain users were added in the Groups section during adding user group members or in the Privileges section during adding privilege holders, they will be automatically added to the list of users in the Users section.

Features of Connecting Domain Users

If the repository is working via PostgreSQL DBMS, to add a domain user set the SSPI or GSS API authentication type:

See also:

Creating User Accounts and Working with Them | Creating and Editing User Account | Editing Service User