Skip to main content

Have AD User bind to AD instead of using a separate account to bind

Comments

3 comments

  • Connor Woolfolk
    Community Manager

    Hello Troy,

    Currently, Cerberus actually does already use the AD user's credentials when trying to authenticate, as logins are impersonated. This is actually why you cannot reset active directory user passwords straight through the UI. That bind account serves as a link between Cerberus and AD, if a service account is not in place to do as much, and takes care of querying the domain controller. 

    From what it sounds like, are you looking to have each AD user able to query the domain controller, so a bind/service account does not need to do so? 

    0
  • Troy Ison

    That is correct.

    Our security teams sees the service account that is in the Binding Options creating the connection to the AD doing the log into AD, then the user authenticating.  However, they want to see the user being the one to connect to AD instead.

     

    0
  • Connor Woolfolk
    Community Manager

    Hello Troy,

    I am going to go ahead and formulate a ticket based on this request, as we may need to ask for a bit more specific information around this ask.

    0

Please sign in to leave a comment.