Community discussions

MikroTik App
 
mikruser
Long time Member
Long time Member
Topic Author
Posts: 578
Joined: Wed Jan 16, 2013 6:28 pm

Feature request: Active Directory integration for RB management

Tue Jun 21, 2016 11:55 am

Hello,

I have Active Directory with "Admin" and "Support" groups.
I want to give Full rights to RB management for all users in "Admin" group, and Read-only rights for all users in "Support" group.
 
andriys
Forum Guru
Forum Guru
Posts: 1527
Joined: Thu Nov 24, 2011 1:59 pm
Location: Kharkiv, Ukraine

Re: Feature request: Active Directory integration for RB management

Tue Jun 21, 2016 12:21 pm

This must already be supported via RADIUS.
Use Mikrotik-Group RADIUS attribute for access rights assignment.
 
mikruser
Long time Member
Long time Member
Topic Author
Posts: 578
Joined: Wed Jan 16, 2013 6:28 pm

Re: Feature request: Active Directory integration for RB management

Tue Jun 21, 2016 1:24 pm

I do not have Radius and do not plan to install it.
 
andriys
Forum Guru
Forum Guru
Posts: 1527
Joined: Thu Nov 24, 2011 1:59 pm
Location: Kharkiv, Ukraine

Re: Feature request: Active Directory integration for RB management

Tue Jun 21, 2016 2:10 pm

Add NPS (previously IAS) role to your AD. It implements RADIUS, which is one of the industry standard ways for AAA integration.
Implementing Kerberos on a router for the purpose of authenticating admins and support engineers sounds quite pointless, IMO.

Anyways, you may have reasons to ask for Kerberos integration (single sign-on, for instance), but please be more specific next time you are asking for a new feature, since AD integration is apparently already supported via RADIUS.

Who is online

Users browsing this forum: Bing [Bot], bpwl, chindo, Google [Bot] and 59 guests