Giving start rights to Active Directory groups

  • 4 March 2008
  • 4 replies
  • 0 views

Badge +2
Is it possible to give an AD group start rights on a process? I have added the group to the process rights list, and ticked "Start" and "View Part", and it seems to have been accepted (and shown as type "Group"), and have saved it! However, I asked a colleague (whose account is in the AD group) to test a workflow and got an error saying he didn't have start rights. When I added him as a separate user it worked fine. Is there something else I need to be doing to get AD groups working?

thanks

Simon

4 replies

Badge +5
Are you using distribution lists or security groups. It should work with security (mail enabled) groups.
Badge +8

Is your colleague a direct member of this group, or a member of a nested group? In the latter case, you'll need to enable nested groups resolution (see http://k2underground.com/forums/thread/21125.aspx).


However, it may be an awful performance drain (if all your groups are in the same domain, it shouldn't be a problem, but as we do have nested groups across worldspread AD domains, it's really terrible).

Badge +7
Hi Nicolas,

this has fixed exactly the same problem Simon raised for me, so Simon, give that a go..

Martin
Badge +2
Turns out it was a nested group and that fix has worked, thanks!!! Fortunately the groups are on the same domain, but I will keep an eye on the performance and see what happens....

Simon

Reply