Security Compliance

Active Directory login fails when using existing group

This article provides instructions to resolve an issue when Active Directory (AD) users cannot log in to SEM when using one of the existing default groups in AD.

First published date

10/29/2018 7:17 PM

Last published date

9/30/2021 9:47 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).
Active Directory (AD) users cannot log in to SEM when using one of the existing default groups in AD.

Product section

Security Event Manager

Resolution

When logging in to the SEM web console with AD credentials, it is important that the user account in AD is not a member of the Primary group which is different than the group used for SEM administrators (for login).

 

  • To configure LDAP configuration: access SEM through https://<hostname-of-sem:8443/mvc/login
  • The optional Admin Group (specified as one of the default AD groups) can specify the Active Directory group that would have admin login to the SEM GUI-console.

On a domain controller:

  1. Open Active Directory Users & Computers.
  2. Select the user to log in to the SEM web console.
  3. Right-click and select the Member Of tab.

    Note the Primary Group, which should not be the same group of users that that are able to log in to the SEM web console.

  • If it is the same, be sure to change it.
  • If for some reason you are unable to change the group membership, you would need to use another group or create a group of the users that will log into the SEM GUI-console.