I am experiencing a problem with approvals in a hybrid environment with Active Directory and Microsoft Entra that is synchronized.

If I request to be added to a AD Group, approval shows for my approving user account when browsing Adaxes.

If I request to be added to a Entra Group, approval does not show for my approving user account when browsing Adaxes.

Is this possibly because when I login to Adaxes to approve I am always and automatically logged on as my AD user account and therefore cannot see the approvals for Entra AD because it is tied to my Entra user account despite being the one and same identity?

Edit: Just found out that I have in fact asked about this in the past in https://www.adaxes.com/questions/13709/how-to-deal-with-approval-requests-in-ad-and-aad-environment and I am curious in that case if this is still not fixed or has a work-around?

ago by (180 points)

1 Answer

ago by (307k points)
0 votes

Hello Daniel,

The feature was introduced in Adaxes 2025.1. If an on-premises user logs in into Adaxes and there are existing approval requests where the synchronized Microsoft Entra account is approver, the requests will be displayed.

ago by (180 points)
0

Great news in that case. I am using version 3.17.23627.0 and I am not seeing any pending approvals related to Microsoft Entra when logged on the the web interface. I do see the ones related to Active Directory.

ago by (307k points)
0

Hello Daniel,

To help us troubleshoot the issue, please, send us (support@adaxes.com) a copy of the Adaxes event log in EVTX format. For information on how to view the log, have a look at the following help article: https://www.adaxes.com/help/ServiceEventLog.

Related questions

In 2025.1 on the web interface, Entra AD no longer appears as a managed domain, though our local AD still functions correctly. Entra users can still be found via search, but ... Entra AD Please also note this was working before the update to 2025.1 from 2023.2

asked Apr 15 by Biagi_IT (20 points)
0 votes
1 answer

Can you let me know how to simultaneously add a value to a custom attribute to both the AD and Entra user objects? The graphical interface update only does it to the AD user object. Thanks.

asked Mar 25 by msheppard (880 points)
0 votes
1 answer

I am trying to get a better understanding of how all this works, so forgive me if some of these questions don't make sense. We are trying to remove our final Exchange On ... to the cloud, then I would need to keep our last on-prem exchange server running?

asked Jan 9 by emeisner (160 points)
0 votes
1 answer

As part of offboarding a user I need to generate a report of all AD groups, Entra groups and all Azure / M365 roles and licenses the user has before they ... about keeping a record of the leavers configured profile to simplify cloning them onto new starters.

asked Jun 24, 2024 by dhardyuk (20 points)
0 votes
1 answer

Hi, our user objects are synced from HR system into AD and generated by a middleware - would a business rule "After creating a user" be triggered in this way or not? Looks ... for this? I need to control those tasks and would like to exit in case of issues

asked Jun 5, 2023 by wintec01 (2.4k points)
0 votes
1 answer