SSO with "log on to" restriction in AD

  • 25 March 2015
  • 8 replies
  • 126 views

I have single sign on enabled, and it works fine... But is not working with users that have in the AD Account tab the restriction to "log on to" only certain computers. If they have everywhere, it works fine.. But if they have the restriction then it asks for the user and password, and even if you enter the credentials it keeps asking and they can't logon to sysaid.

We tried adding the active directory server and the sysaid server to the list of allowed computers to log on... but no luck. Same result.

Any ideas please?

8 replies

I hope this is not the case, we are looking into deploying this as well very shortly, especially to restrict a lot of servers.
Does the browser ask for credentials or does it take you to the sysaid login screen?
The browser asks for credentials. And even if you put them, still keeps asking making it impossible to log in.
Hey SA Consultant,

In order to investigate the issue further, could you try adding "&manual=true" tag to the URL to override SSO and see if the login works?

Let me know of the results.

Thanks,
Danny
Hello Danny,
Thanks for your response...

Right now I dont have SSO enabled. You want me to enabled it and try that??
Hi,

No need. I understand you are currently in contact with our support team regarding this issue, please follow their investigation steps and suggestions and let me know should you need anything else :)

Thanks,
Danny
If there is something that we need to do to make this work as well, please post it here if there is a resolution.
We are in the process setting this up for certain users and would like them to be able to use sysaid.
In case anyone happens to stumble upon this again:

You can try and add the domain controllers to the logon to restriction in Active Directory and that should make it so you can successfully log into SysAid with a restricted user.

Reply