Last Modified: Nov 22, 2021
Affected Product(s):
BIG-IP APM
Fixed In:
12.0.0
Opened: Mar 13, 2015 Severity: 3-Major
if the option "fetch primary group" is enabled for AD Query AND some attributes are configured as "required attributes" then AD Query request only those configured attributes for a user during logon process. If the required attributes missing primaryGroupID attribute, then AD Query will fail as it cannot find primary group DN for the user
AD Query fails
the option "fetch primary group" is enabled for AD Query AND some attributes are configured as "required attributes" AND required attributes missing primaryGroupID attribute
add primaryGroupID attribute to the list of required attributes. it's not necessary if "required attributes" list is empty - in this case, bigip retrieves all attributes for a user including primaryGroupID
None