0 votes

First off I have to say that Adaxes is really extraordinary and has been such a massive help to delegate a lot of the day-to-day AD management across mutiple untrusted forests.

Currently we're using adm-CustomAttributeText3 as our Top Level Node in the Web Interface. We have business rules that set the correct value based on the user type and the OU that their account is located in. Thanks to our OU structure (Domain\Location-Address\Department\Etc.) it's simple to define a Top Level that matches the users Management level.

We are hitting a snag when we get to Technicians that support all locations in all domains however. If we attempt to use (CN=Managed Domains,CN=Configuration Objects,CN=Adaxes Configuration,CN=Adaxes) for the Top Level node we get "Managed Domains is not a valid object". If we add each domain to a business unit we can set the DN of BU to top level node but this breaks the browsing ability, instead you click on that BU and get new page, then click domain and get new page, now you can drill down.

So I wanted to see if anyone knows if there is a DN for all Managed Domain which we could use for our Technicians Top Level Node in the Web Portal? Or if this is the wrong approach and you know of a better way to get the same result (while keeping our OU structures), please let me know. I'm still fairly new to Adaxes and have a lot to learn about how it functions under the hood, and a lot of SDK documentation left to read.

by (20 points)

1 Answer

0 votes
by (295k points)

Hello,

First off I have to say that Adaxes is really extraordinary and has been such a massive help to delegate a lot of the day-to-day AD management across mutiple untrusted forests.

Thank you for your good words, it is much appreciated! We do our best to provide highest level service to our customers.

So I wanted to see if anyone knows if there is a DN for all Managed Domain which we could use for our Technicians Top Level Node in the Web Portal?

Unfortunately, there is no such thing. For such cases, it is recommended to have two separate Web interfaces. One will be configured as you have it now and will only be accessed by the corresponding users. The other one will not have a top level node at all and will be accessed only by technicians. For details on how to configure user access to Web interface, have a look at the following tutorial: https://www.adaxes.com/help/AllowDenyAccessToTheWebInterface.

Related questions

0 votes
1 answer

Hi I've created a new adaxes configuration and limited access to do things based on the 'actions' section: only create, modify, delete contacts are available. Added myself to ... since updating to version 3.16.21408.0. How can I resolve this error? Thanks

asked Oct 4, 2023 by cheezoid (20 points)
0 votes
1 answer

Is it possible to grant selected user option to add custom license plan (or just subset of its licenses) to given user(s) using web interface?

asked Feb 28, 2023 by KIT (960 points)
0 votes
1 answer

Hello, Is it possible to have a variable or custom field that I could use and reference from multiple PowerShell scripts? For example, I want to have two custom commands, ... It could be something system wide or maybe local to the scheduled task? Thanks! Ryan

asked Jun 4, 2019 by ryan_breneman (920 points)
0 votes
1 answer

Will it use 1 license for an Active Directory user and his azure account or 2 licenses?

asked Nov 7, 2023 by johanpr (120 points)
0 votes
1 answer

Hi, We're looking at using Adaxes in an MSP environment with around 30 clients, each with their own domain. Some of these clients are hybrid on-prem/Azure, while ... the internet on the client DC servers - are there security implications here? Thanks, Max

asked Sep 7, 2023 by mcutlyp (40 points)
3,605 questions
3,292 answers
8,342 comments
548,452 users