We've recently upgrade from License Manager 8.3 to Directory Server 10. I've set up Active Directory as an Identity Provider and have a couple of AD groups synchronizing correctly to assign Full and Forms Authenticated Participant licenses. I've created groups in the Directory Server (Accounts...Groups...Add), but I can't figure out how to map the group membership to an Active Directory group. I need to be able to map, for example, our AD Named Users group to the Directory Server Named Users group so that members will populate automatically from AD. Additionally, in Forms Administration I need to be able to map Teams (under Team Management) to AD groups. Either the functionality doesn't exist or I'm missing where to configure it.
Question
Question
Directory Server and Forms 10 Mapping to Active Directory Groups
Replies
With Forms 11 Update 2(https://support.laserfiche.com/kb/1014352/list-of-changes-for-laserfiche-forms-11-update-2), you can add AD group to team and the users in the AD group will be automatically synchronized so the users from the AD group can participant in the team such as get email notification when task is assigned to the team, take team tasks etc.
It seems like you have two questions here: 1) cam AD users map to Directory Server Groups (for the purpose of synching to Forms) and 2) can AD groups be mapped to Teams
To answer (1):
In the current release of Directory Server and Forms, you need to manually add users to the Directory Server group(s) you have chosen sync in Forms. We are looking to improve this behavior in the future, possibly by allowing AD groups to be added directly to Directory Server groups and/or by improving the sync behavior in Forms.
I will defer question (2) to someone from our Forms team.
Thanks for the information Brianna. The lack of AD sync with Directory Server groups is a major shortcoming and should be put high on the enhancement request list.
I second this. This is terrible functionality. With almost 5000 users, we have to add them one by one to a group?
Any more movement on this in regards to Syncing AD Groups to Forms Teams??
Team Management is starting to get hairy with the 5000+ Forms Participants.
As of LFDS 10.2 (released early last year), you can add AD groups directly to an LFDS group. I believe you need Forms 10.2.1 as well.
This allows you to select the AD groups to sync to Forms, or to mirror the parts of AD you need in Forms by adding them to equivalent groups LFDS.
@Brianna Blanchard
We are using that and have that setup for licensing and getting them registered to the platform. How about anything in regards to actually syncing Teams with members or even Roles?
I see in the new 10.4 Feature List that they've seemingly created a new UI Console to manage Teams & Members. (Woohoo!!!) Was hoping to see something about syncing/automating some of the Team Management.
Unfortunately Forms Teams do not yet have the capability to sync with AD groups. It is a fairly common request and we'll look to get to it as soon as possible.
Thank you for your response @████████! As an organization with the Educational User Licenses (10,000+), we look forward to being able to better manage our Forms implementation as it relates to various processes.
It's been 4.5 years since I started this thread. I really need to be able to populate Forms Teams and Roles from Active Directory. Will this ever happen? Has anyone developed some sort of workaround? Thanks for any info that you can provide.
Unfortunately, we had to drop Laserfiche forms and go with a different solution. This feature was a must and we waited long enough to see it implemented.
Is there any updates on adding Directory Server groups to the AD sync rules. It still only shows Organization with no option to add groups, but Forms only knows how to read from Groups.
Is there an update on this topic?
Is it possible to link Directory Server groups to Forms own tasks or do I have to create teams and assign user by user? This involves performing multiple security and assignment processes throughout the Laserfiche environment.
@████████ With Forms 11 next update(target to be released early next year), you will have the option to allow everyone to sign in Forms so you will no longer need to add a user to LFDS group during AD sync.
@████████, Forms 11 next update(target to be released early next year) will include the feature of adding groups to teams.