Assign user label on LDAP user import
Using the K1000, I currently have a scheduled user import from our active directory. It imports all users, and a few labels based on the "memberOf" attribute. It's bringing in the labels I want but it's not assigning users to it. So i'm trying to figure out how to keep the users in the proper labels based on user group. Example, anyone in the domain group "Helpdesk" should have the ldap_Helpdesk label associated with them.
Also, is there a way to force a role based on ldap label or group membership? I've noticed once a user is imported and assigned a role, that role is perminent until you go in an manually change it to something else. So I setup a second LDAP import for anyone in the "Desktop Support" domain group will be given the "Desktop" role I created (for inventory and asset management access to the Admin Portal)
Answers (3)
LDAP labels are applied to users when they login to KACE, not when imported. I would love to have them assigned at import, since the vast majority of our users don't ever login to KACE, but alas, that's not how the system is designed.
Comments:
-
Then I don't understand why they have the ability to import labels. What's the point? - mgomez 11 years ago
-
The system is designed around people logging into KACE and labels being applied at that time. It's similar to how machine smart labels are applied when a computer checks in. - chucksteel 11 years ago