Integrating security groups with Active Directory groups
Who is this article for?Administrators responsible for user management.
Administration module access is needed.
System is based around the permissions that can be added directly, through groups, or inherited based on the user's relationship to the record.
Security groups can be linked to Active Directory (AD) groups, assigning access based on their Active Directory membership. This allows access to be controlled as users move throughout your organisation.
This article explains how to integrate the groups and the limitations to look out for before using this user management method.
1. Considerations
Before configuring the integration, be aware that permissions granted through integration will not be displayed through the 'View effective permissions' screen. Users may appear to have no permissions assigned when in reality they are obtaining access through AD integration.
Quality Management also doesn't automatically update permissions inherited due to AD group integration.
If a user is a member of the 'Accounts' group in AD that's associated with the 'Accounts' group in Quality Management, the user inherits permissions from the Quality Management 'Accounts' group.
However, if the user is removed from the 'Accounts' group in AD, the user doesn't automatically lose the permissions previously inherited.
To refresh permissions that should be assigned or removed as part of the integration, restart the Ideagen Quality Management Server service when all users are logged out of Ideagen Quality Management.
2. Integrating groups
To integrate a security group with AD:
- Access the Administration module.
- Select Settings and Defaults (under Security).
- Switch to the Authentication and Security tab.
- Tick Enable association of Quality Management security groups to Active Directory.
- Click OK.
- Select Groups (under Security).
- Double-click the group to integrate.
- Fill out the Associated Active Directory Group field.
Make sure the entered name matches the name of the AD group.
- Click OK.
Only one Active Directory group can be linked with a Quality Management static group at any given time.