We have recently changed our login directory from one domain to another and want to change the Admin group with the "Special permissions" and admin access everywhere to a group in our new login domain but I can't figure out how this is done.
Thanks
If you want to use LDAP groups to set permissions that works fine but please include a group called confluence-administrators in the LDAP directory you migrate to. If you cannot get that group created in LDAP, consider making your LDAP user directory "read-only with local groups" so you can add your admins to the confluence-adminstrators group in the Confluence Internal directory. This article explains in more detail: Confluence Admin Permission Levels Explained
"The confluence-administrators group defines a set of "super users" who can access the Administration Console and perform site-wide administration. Members of this group can also see the content of all pages and spaces in the Confluence instance, regardless of space permissions."
So I can't specify a different group to give the "super user" access to, it has to be called confluence-admins? Any particular reason for the limitation?
If I were to have 2 groups in different LDAP directories both called confluence-admins, how would Confluence handle it?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes, that was what I was trying to say. There are two manadatory groups assigments for Confluence: confluence-admins and confluence-users. You cannot rename them. I figured this out the hard way.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
It just seems so unneccessarily limiting. This doesn't apply in JIRA.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Ann, would having a groups called confluence-admins on two LDAP directories simulatneously cause any issues?
Thanks
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Please read this documentation about the effect of the directory order and the aggregating group memberships setting:
Please note that the doc says:
"Before you move an external directory above Confluence's internal directory, make sure you (and your admin users) are members of a group called confluence-administrators in your external directory or you may accidentally lock yourself out of the Confluence admin console."
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
So my best bet is probably to:
1) Ensure I have a working admin account on the Confluence Internal directory.
2) Rename the group on the LDAP Directory we want to decommission, then sync.
3) Create the new group on the new LDAP Directory and then sync that?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
For 1:
For 2:
For 3:
For the future: I look forward to any follow-up questions.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Sorry, that was a mistake in 1), I meant Confluence local user.
I'll let you know how I get on.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Looks to have all gone fine. Thanks for your help.
As a suggestion, can we have the ability to use any group for admin in future, like we can in Jira. This has made a right mess of our AD naming convention!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Miles,
you configure the basic Jira-admin permissions here:
http://<your-jira-url>/secure/admin/GlobalPermissions!default.jspa
There you can add the admin permissions to new groups. But be careful to not lose your own admin permission by doing this!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I am assuming you are referring to LDAP? As long as whatever group your admins are in, are also members of confluence-admins, you are good to go.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks for the reply. confluence-admins is on a different LDAP domain, the one we're trying to decommission.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.