This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SMC SSP AD Security group change

We have a an active SMC deployment in our environment, with our users registering devices via our SSP. We have 800+ devices registered and all is working well.

When we set up the SMC environment we created a specific AD security group for SSP access, let's call it SophosMobileSSP, that all Domain Users are automatically added to. The problem is that we're seeing some staff not being able to access the SSP and our operations team believe because we've created a two step AD authentication (e.g. SophosMobileSSP AD group just looks up the DomainUsers members) it's causing problems and they recommend we just change the SMC settings so it refers to the DomainUsers group.

I had a look at the System set up menu and it looks relatively straight forward to change the group from SophosMobileSSP to DomainUsers but I do get the usual "The directory configuration can not be modified because 854 devices are still linked to the directory" message and I'm concerned that if I try and change this group that all 800+ devices may need re-enrollment. And nobody has time for that.

Has anyone made this change and experienced problems?

Tl:dr: How serious is the 'don't modify the directory configuration' message?

:55580


This thread was automatically locked due to age.
Parents
  • Good afternoon,

    I don't see anything wrong with the method you're using and if it works for one user it should work for them all.

    Are these users, who cannot authenticate to SSP, new additions to AD? If so were they added via a DC other than the one being used by SMC? If so you may need to force an AD sync before Sophos sees them as members of the relevant group or simply wait for AD replication to take place before the users are able to authenticate.

    I would also ensure these users are attempting to authenticate to the SSP and not the admin portal and are entering their user ID in the correct format.

    Regards.

    :55615
Reply
  • Good afternoon,

    I don't see anything wrong with the method you're using and if it works for one user it should work for them all.

    Are these users, who cannot authenticate to SSP, new additions to AD? If so were they added via a DC other than the one being used by SMC? If so you may need to force an AD sync before Sophos sees them as members of the relevant group or simply wait for AD replication to take place before the users are able to authenticate.

    I would also ensure these users are attempting to authenticate to the SSP and not the admin portal and are entering their user ID in the correct format.

    Regards.

    :55615
Children
No Data