# LDAP group mapping

**URL:** <https://community.datagerry.com/t/ldap-group-mapping/315>\
**Category:** Feature Requests\
**Created:** [April 15, 2021, 12:47pm UTC](https://community.datagerry.com/t/ldap-group-mapping/315 "2021-04-15T12:47:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![anon60115798](https://avatars.discourse-cdn.com/v4/letter/a/bc8723/32.png) [@anon60115798](https://community.datagerry.com/u/anon60115798)\
**Post date:** [April 15, 2021, 12:47pm UTC](https://community.datagerry.com/t/ldap-group-mapping/315/1 "2021-04-15T12:47:51Z")

</div>

Hello everybody,

I would like to use the LDAP group mapping and am struggle to get it up and running. The basic LDAP authentication works correctly: Users will be created (if not exist) on login and assigned the default DataGerry group.

The next step is to enable the group mapping. Referring to the [official admin guide](https://docs.DataGerry.com/latest/admin_guide/authentication.html#ldap-group-mapping), I need to map the LDAP group with the DataGerry internal group (Got this part 😉). The search filter field above this very mapping table confuses me.  
DataGerry seems to rely on a ldap backend that searches for groups based on usernames. A quick look into the source code on GitHub strengthens me in my assumption. At the moment I am concerned that this DataGerry feature does not work for my environment and to me it looks like an issue in the application.

In my infrastructure there is an Active Directory that does not have a `group object -> username` relationship. It’s more a `user object <-> group object` relationship. I am not sure if this is by-design or just in this particular Active Directory. On every user object there is the `memberOf` attribute. It can exist multiple times and contains a reference (distinguished name) to a single group. So each group membership is represented by a separate `memberOf` attribute in a user object. In addition to that a group object has multiple `member` attributes each containing a reference (distinguished name) to a specific user.

I don’t know any possible way to “convert” the username provided by DataGerry into an actual user inside the search filter defined in DataGerry. This would be necessary for me to find all groups having the users “distinguished name” in a `memberOf` attribute.

Did I got this whole feature totally wrong? Is there any chance to get this feature up and running in my current environment?

Happy for your feedback.

And just one another question: Is it intended that Firstname, Lastname and Email should also be imported via LDAP? Currently these fields remain empty.

Thank you very much in advance!

Best regards

---

<div class="post-metadata">

**Author:** ![haldi](https://avatars.discourse-cdn.com/v4/letter/h/34f0e0/32.png) [@haldi](https://community.datagerry.com/u/haldi)\
**Post date:** [November 12, 2021, 10:58am UTC](https://community.datagerry.com/t/ldap-group-mapping/315/2 "2021-11-12T10:58:56Z")

</div>

Hey @anon60115798,

were you able to solve this problem? We are trying the exact same approach, but only got it working using the _DistinguishedName_ as Loginuser, which isn’t practicable.  
e.g. CN=Full Username,OU=Path03,OU=Path02,OU=Path01,DC=ad,DC=contoso,DC=com"

Thanks,  
Ruben

---

<div class="post-metadata">

**Author:** ![MR\_GamBit](https://avatars.discourse-cdn.com/v4/letter/m/48db29/32.png) [@MR\_GamBit](https://community.datagerry.com/u/MR_GamBit)\
**Post date:** [April 18, 2023, 2:20pm UTC](https://community.datagerry.com/t/ldap-group-mapping/315/3 "2023-04-18T14:20:03Z")

</div>

I have changed the Searchfilter for the users to (SamAccountName=%username%).  
With that my ad-users can login.  
At the moment i try to get the group assignment right.  
Im stuck with “MemberOf” seams not to work.  
I will inform you if i find a solution.

---

<div class="post-metadata">

**Author:** ![jmatys](https://avatars.discourse-cdn.com/v4/letter/j/839c29/32.png) [@jmatys](https://community.datagerry.com/u/jmatys)\
**Post date:** [June 21, 2024, 8:19am UTC](https://community.datagerry.com/t/ldap-group-mapping/315/5 "2024-06-21T08:19:58Z")

</div>

We limit the users to one AD group - Searchfilter: (&(sAMAccountName=%username%)(memberOf=CN=…DC=com)) and then we manually assign the user to the role as the AD memberOf does not contain the username in our case, so it could not be mapped to the group.
