While searching for user access analysis options I came across another discussion from December referencing the use of Active Directory Groups.
Does anyone have any additional information detailing this practice?
It is possible technically,but I am not sure it is recommended because of many reasons. 1. Opening the JNDI adapter to search for groups and granting Windchill Security based on that would have performance impact as AD has large number of groups which not be relevant to Windchill. 2. Some companies add certain characters to group names which will not work good with Windchill. 3. I know Windchill had issues in handling nested group references in Active Directory. 4.This also takes away the right of managing windchill access& Security from Windchill Administrator to AD Administrator.
On the other hand if you are talking about creating a group in active directory to grant access to Windchill through LDAP filters, that is most widely used approach.
Thank you
Binesh Kumar
Barry Wehmiller