Hi,
We are using AD Groups to define user access within AX (AD users are members of AD groups and those AD groups are setup in AX defining each security role). This is working, however, Management Reporter will not pull in (integrate) the user from AX unless we manually assign a security role to that user. Will MR not sync with the roles that are applied to a user from the AD group? We don't have a problem with manually assigning the roles, but it does take away the AX User automation. Perhaps we're doing something incorrectly?
We're on R3 CU13.
*This post is locked for comments
I had seen a statement about the SoD in the past. As a database sync is not aware which users are part of which AD group, the only way to do the user sync is based on assignment of roles on the users themselves.
Thanks for the quick response, André Arnaud de Calavon!
Does Microsoft outline this downside in any documentation (friendly curiosity)? I haven't seen any, but perhaps I'm just not looking in the right spot.
Hi JrDAXmike,
The AD group assignment has some downsides. MR user integration is indeed looking at assigned roles to users directly. Also the Segregation of Duties is not working together with AD group users.
Stay up to date on forum activity by subscribing. You can also customize your in-app and email Notification settings across all subscriptions.
André Arnaud de Cal... 291,240 Super User 2024 Season 2
Martin Dráb 230,149 Most Valuable Professional
nmaenpaa 101,156