We have about 150 locations, each with their own OU structure and Business Unit in Adaxes.
The admins, we delegate access to, may have access over one or several of these OU structures and business units.
We recently found that once you have accss to several business units, it starts to significantly impact performance of the user interface.
In one example, an admin has access over 25 Business Units, and when opening the Adaxes console (desktop or web), it takes seconds for each domain node or OU to start listing out in the tree view. And everything else is just as slow.
I've done a lot of testing with different concepts of security roles and how to apply them to users/groups, and narrowed it down to one thing:
Once I give someone Read, List Object and Read Logging Information over several BUs, with a scope of "This object only" and "Subtree", it slows down the overall interface everywhere, even when just accessing AD and not working with BUs at all.
I can keep those security role assignments in place, and just put in another role assignment to grant the same access over all BUs, at the parent container level, and then performance is fine.
But with having 150+ of these BUs, I'd prefer to let the admins only see what they have access to.
Is there a known issue/effect behind this and a way to work around it?
Adaxes Version 2025.1 - 3.17.23904.0
Multi-Server setup (3 servers)
AD Forest with 4 subdomains and 1 Entra ID tenant