Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Users' active directory groups not updating

lmock01
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 26, 2013

When a new user is created in Active Directory, Confluence pulls all of the user and group membership info correctly. But if the user is added to or removed from a group, the change is not reflected in Confluence, even if I click the "synchronize" button.

We're on Confluence 5.1.4.

I have set it up to authenticate users against our Active Directory ldap in readonly mode.

Our AD has more than 5k users, so I limited the sync to only those people that are a member of a specific AD group via the User Object Filter. Otherwise, all of the settings are left as default. The LDAP is set as read only.

(&(objectCategory=Person)(sAMAccountName=*)(memberOf=CN=Confluence Editors,OU=Groups,OU=USA,DC=americas,DC=com))

I checked the logs and do not see any errors. The synchronization shows as successful.

I assume I'm missing something obvious. Any ideas?

2 answers

0 votes
krishk August 30, 2013

I am facing similar issues - in the User Schema settings, instead of objectCategory=Person, try objectClass=User. This seems to get me the most recent member list (added / deleted) from the group on manually synchronising - however, the automated sync part still doesn't work. Confluence version - 5.1.5

0 votes
Daniel Borcherding
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 26, 2013

Laura,

My guess would be that your Group Object Class may not be right.

https://confluence.atlassian.com/display/DOC/Connecting+to+an+LDAP+Directory

Please make sure that thisis set correctly so that Confluence knows what group objects look like.

Also have your run that filter in an LDAP browser tool like Apache Directory Studio?

http://directory.apache.org/studio/

What are the results?

To better troubleshoot this you will need a direcotry configuration summary and an LDIF of one of the members that is supposed to have their groups synced but is not working.

https://confluence.atlassian.com/display/CONFKB/How+to+Generate+a++Directory+Configuration+Summary

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events