<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WFA LDAP Groups - Allow 'Domain Users' to login in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/WFA-LDAP-Groups-Allow-Domain-Users-to-login/m-p/129330#M23293</link>
    <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/55277"&gt;@ChadPruden&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Separation of LDAP Groups management was done in WFA4.1. But for backword compatibility of APIs, we have kept the API same as before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The WFA Domain groups can be Added using the api &lt;FONT color="#FF0000"&gt;&lt;EM&gt;/system/ldap&lt;/EM&gt;&lt;/FONT&gt; on method PUT. On swagger doc you can see it under &lt;FONT color="#FF0000"&gt;System Operations -&amp;gt; User Management&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This API will set your LDAP authentication along with the LDAP groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if you want to add another LDAP group to the existing list via APIs, do the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming your LDAP Authentication is already enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Do a GET on&amp;nbsp;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt; /system/ldap&lt;/FONT&gt; to get the current configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. On the response body, Add your new group for the specific role&lt;/SPAN&gt;&lt;SPAN&gt;. Since you want resticted Catgory based access, you should add it into&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="hljs-tag"&gt;&amp;lt;&lt;SPAN class="hljs-name"&gt;operatorGroups&lt;/SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. Call POST on &lt;FONT color="#FF0000"&gt;&lt;EM&gt;/system/ldap&lt;/EM&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Done.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;API /system/ldap will show the groups. Also /system/ldap_group will also get this Group in response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sinhaa&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2017 06:15:23 GMT</pubDate>
    <dc:creator>sinhaa</dc:creator>
    <dc:date>2017-03-23T06:15:23Z</dc:date>
    <item>
      <title>WFA LDAP Groups - Allow 'Domain Users' to login</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/WFA-LDAP-Groups-Allow-Domain-Users-to-login/m-p/129321#M23291</link>
      <description>&lt;P&gt;Looking for a way to allow anyone in our company the ability to login to WFA... we will then restricting what they can see/do by securing the Categories, or within the workflows themselves. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Otherwise, we'd want to leverage an API call to add new LDAP group, but looking at Swagger docs, doesn't seem there is a PUT /rest/ldap_group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WFA 4.1RC&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 15:17:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/WFA-LDAP-Groups-Allow-Domain-Users-to-login/m-p/129321#M23291</guid>
      <dc:creator>ChadPruden</dc:creator>
      <dc:date>2025-06-04T15:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: WFA LDAP Groups - Allow 'Domain Users' to login</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/WFA-LDAP-Groups-Allow-Domain-Users-to-login/m-p/129330#M23293</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/55277"&gt;@ChadPruden&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Separation of LDAP Groups management was done in WFA4.1. But for backword compatibility of APIs, we have kept the API same as before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The WFA Domain groups can be Added using the api &lt;FONT color="#FF0000"&gt;&lt;EM&gt;/system/ldap&lt;/EM&gt;&lt;/FONT&gt; on method PUT. On swagger doc you can see it under &lt;FONT color="#FF0000"&gt;System Operations -&amp;gt; User Management&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This API will set your LDAP authentication along with the LDAP groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if you want to add another LDAP group to the existing list via APIs, do the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming your LDAP Authentication is already enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Do a GET on&amp;nbsp;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt; /system/ldap&lt;/FONT&gt; to get the current configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. On the response body, Add your new group for the specific role&lt;/SPAN&gt;&lt;SPAN&gt;. Since you want resticted Catgory based access, you should add it into&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="hljs-tag"&gt;&amp;lt;&lt;SPAN class="hljs-name"&gt;operatorGroups&lt;/SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. Call POST on &lt;FONT color="#FF0000"&gt;&lt;EM&gt;/system/ldap&lt;/EM&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Done.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;API /system/ldap will show the groups. Also /system/ldap_group will also get this Group in response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sinhaa&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 06:15:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/WFA-LDAP-Groups-Allow-Domain-Users-to-login/m-p/129330#M23293</guid>
      <dc:creator>sinhaa</dc:creator>
      <dc:date>2017-03-23T06:15:23Z</dc:date>
    </item>
  </channel>
</rss>

