User in different AD groups

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

User in different AD groups

L0 Member

Hi,

we want to enforce a policy with user groups from AD. USER ID actually works fine.

The following scenario: A single User (e.g. Harry) belongs to different AD groups (e.g. group1 & group2). The policy works with different URL Filtering profiles.

Policy 1 will have Source "group1" and Policy 2 will have Source "group2" as Objects.

Policy 1 is positioned before Policy 2. If User Harry wants to try to reach an URL which is allowed in Policy 2 (group2) it will never match, because Policy 1 matches always for that User regardless if the URL is allowed or blocked.

Has anyone an idea to fix?

Thanks

Stefan

1 accepted solution

Accepted Solutions

L4 Transporter

Hi Stefan,

Today you need to create an exception URL Profile and Security Rule to handle these types of cases.  It is not pretty, but it does work.  There will be enhancements to help simplify this type of policy in a future release.  It is possible it may come before the end of this year.

Cheers,

Kelly

View solution in original post

1 REPLY 1

L4 Transporter

Hi Stefan,

Today you need to create an exception URL Profile and Security Rule to handle these types of cases.  It is not pretty, but it does work.  There will be enhancements to help simplify this type of policy in a future release.  It is possible it may come before the end of this year.

Cheers,

Kelly

  • 1 accepted solution
  • 2044 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!