0 votes


Trying to figure out what controls "look in" field and why no OU's are shown.
Logged in user on the WebUI is a user administrator role.

No OU's are shown:

1 - when selecting groups for one or more selected users. This could help the given user administrator to narrow the selection, because the groups are organized in an OU hierarchy:

2 - when selecting users to become member of a group.: This could help the given user administrator to narrow the selection, because the users are organized in an OU hierarchy:

What am I missing here ?

- Thanks

by (2.6k points)

1 Answer

0 votes
by (216k points)
selected by
Best answer

It looks like the user has permissions to view objects deeply within the AD structure, but doesn’t have appropriate permissions to view objects located directly under the directory root. Since the Look In section starts browsing from the root of your domain, the user needs permissions to view all containers from the domain root down to the OU where the users are located. For example, if users are located in OU TESTDOM/Offices/Afdeling AA, to be able to browse to the necessary OU in the directory tree, the user needs at least the permissions to view your domain, the Offices OU and the Afdeling AA OU.

By default, the permissions to view all objects is granted by a built-in Security Role called Domain User. Probably, you’ve disabled it or changed its Assignment Scope. If you’ve assigned your users the built-in Account Manager Security Role, it already contains a permission to view any objects (Read – All object types), so you simply need to include the necessary OU objects in the Assignment Scope of the Role. To do this:

  1. In the Console Tree of the Administration Console, select the Security Role. The role Assignments will appear in the Result Pane (located to the right).
  2. Click Add Assignment.
  3. In the Select Trustee dialog box, select a user or group whom you want to grant the permissions and click OK.
  4. In the Specify Assignment Scope dialog box, select one of the Organizational Units a user needs to view.
  5. Click Add.
  6. In the Assignment Options window, select This Organizational-Unit object. Click OK.
  7. Repeat steps 4-6 for all OUs located from the domain root to the OU the user has administrative permissions in.
  8. Save the Security Role.


Thanks. This gives access to the whole path of folders and the targets, all right.

However, we do not want the WebUI users to view and expand all folders in the path, only the target folder, it's subfolders and objects.

Obviously, we could reorganize our AD to match our needs, but - in my opinion - this issue could be solved nicely, by adding target selction criterias, as used elsewhere.

Just a thought :-)

- Regards

Related questions

0 votes
1 answer

This FAQ https://www.adaxes.com/questions/1004/how-to-set-look-in-everywhere-in-the-look-in-textbox does not apply to current versions of adaxes. Is there any way I can set "Everywhere" as default in Adaxes 2023.2?

asked Jan 8, 2024 by funfact (20 points)
0 votes
1 answer

When attempting to add a business unit as a trustee for a security role, it is not visible under the "Look in" drop down in the Assign Role window.

asked Jul 20, 2021 by ryan741 (120 points)
0 votes
1 answer

When administrator tries to add a person to a group the search bar "Look in" textbox defaults to the group container. Is there a way to set the "Look in" textbox to default to "Everywhere" instead of the group container?

asked Jul 24, 2015 by lgibbens (320 points)
0 votes
1 answer

Hi! What am I missing, we are running 2018.2, we've edited a webform using web interface configurator. I've added the telephone field in section general under Management heading ( ... it to both modify tab and create tab. Any hints what I'm doing wrong? /Kaj

asked Jul 10, 2019 by KajLehtinen (650 points)
0 votes
1 answer

Hello, We have a problem with the way Adaxes detects % as variables in all PowerShell scripts. We are configuring a HTML email template for all out going emails from the system ... this is a start of a variable. Is there anyway around this? Regards, ice-dog

asked Feb 22, 2019 by ice-dog (170 points)
3,638 questions
3,326 answers
548,846 users