Book a Demo

Author Topic: Synchronising EA Security with AD Security  (Read 3162 times)

Paolo F Cantoni

  • EA Guru
  • *****
  • Posts: 8626
  • Karma: +259/-129
  • Inconsistently correct systems DON'T EXIST!
    • View Profile
Synchronising EA Security with AD Security
« on: September 24, 2015, 11:46:29 am »
As I understand it, once I've imported a user from AD, EA will set their user name AND password to the AD settings.

Fine.

If the User changes their AD password, is the new password available to EA or do I have to delete and re-import the user?

If the latter, it seems to me that it would be best fotr the user to go into EA using their previous password and change it tot he new one manually.  Is that correct?

I also understand v12.1 will make life a bit easier in the Security Area, however, will it eliminate this problem?

TIA,
Paolo
Inconsistently correct systems DON'T EXIST!
... Therefore, aim for consistency; in the expectation of achieving correctness....
-Semantica-
Helsinki Principle Rules!

Aaron B

  • EA Administrator
  • EA User
  • *****
  • Posts: 941
  • Karma: +18/-0
    • View Profile
Re: Synchronising EA Security with AD Security
« Reply #1 on: September 24, 2015, 12:33:17 pm »
EA does not import the password from AD.  When you first import a user from AD it sets a randomized password value to prevent forced login with this account.  If you want to allow a user to manually login to EA with this account, the admin will need to set a password after import.

If the Use Windows Authentication option is enabled, when you open the project in EA it will compare your current Windows login against the list of userIDs stored in your EA model.  If it finds a match, you are logged in automatically.  No passwords are used during this process, so it doesn't matter if your AD password has since changed.

Paolo F Cantoni

  • EA Guru
  • *****
  • Posts: 8626
  • Karma: +259/-129
  • Inconsistently correct systems DON'T EXIST!
    • View Profile
Re: Synchronising EA Security with AD Security
« Reply #2 on: September 24, 2015, 12:36:50 pm »
Thanks for clarifying that Aaron.

So the reason my user couldn't log in after a recent change of password in AD wasn't because of that...

[edit]Further analysis since I posted the original post confirms that the problem wasn't related to AD authentication.  "I didn't change anything - honest!  ;)[/edit]

Paolo
Inconsistently correct systems DON'T EXIST!
... Therefore, aim for consistency; in the expectation of achieving correctness....
-Semantica-
Helsinki Principle Rules!