Can Active Directory users be configured as logins for GUI?

mjpagan

Cadet
Joined
Feb 23, 2021
Messages
2
I have connected my TrueNAS 11.3.U5 appliance to Active Directory and I can see the domain users via the shell. The Active Directory users are not showing under users. Is it possible to grant Active Directory users admin roles? I have hunted in the UI and cannot find my domain users so I can add them to groups. Am I trying to do something that is not possible?
 

Ericloewe

Server Wrangler
Moderator
Joined
Feb 15, 2014
Messages
20,194
No, despite this being a frequent request.
 

sretalla

Powered by Neutrality
Moderator
Joined
Jan 1, 2016
Messages
9,703
The GUI only supports root as the login.

If you wish to limit the granted rights of accounts to administer TrueNAS or FreeNAS servers, consider using the Role Based Access Control in TrueCommand.
 

anodos

Sambassador
iXsystems
Joined
Mar 6, 2014
Messages
9,554
There are certain types of administrative actions that can be performed through "Computer Management" from a Windows client. It depends on what sorts of administrative actions are needed. I have some sample scripts in 12 that can be plumbed through smb.conf auxiliary parameters to add / remove local users and add / remove SMB shares. User in this case will need SEC_PRIV_DISK_OPERATOR (domain admins).
 

mjpagan

Cadet
Joined
Feb 23, 2021
Messages
2
Well that explains why I couldn't find the settings I guess :)

I would be helpful from a security standpoint to be able to use a directory to have less places to control administrative functions, but maybe someday it will be added.

Thanks for the answers, folks.
 
Top