What is this?

This knowledgebase contains questions and answers about PRTG Network Monitor and network monitoring in general.

Learn more

PRTG Network Monitor

Intuitive to Use. Easy to manage.
More than 500,000 users rely on Paessler PRTG every day. Find out how you can reduce cost, increase QoS and ease planning, as well.

Free Download

Top Tags


View all Tags

Active directory Group Changes

Votes:

10

Hi,

we are running PRTG in the latest 14 Version with an AD Setup. On start with PRTG i created multiple Groups to get status messages to different supporters (e.g. our Intranet Devs getting Intranet Service related messages etc.) and to get different rights on the sensors (we are running >3000 Sensors).

Now i have to change one of the supporters. I changed my AD Group, but PRTG does not recognize the change. How can i get PRTG to get my changed AD Group?

best regards

pstuerze

ad group membership prtg user

Created on Nov 14, 2014 11:36:22 AM



19 Replies

Votes:

0

Hello,

PRTG synchronizes with the Active Directory when the AD User tries to login the PRTG interface. The user will be shown in the AD-Group in PRTG after the first login.

Best regards

Created on Nov 14, 2014 12:12:02 PM by  Felix Saure [Paessler Support]



Votes:

2

Hi,

yes, after the first logon, all users are in my groups. But after that first login, how can i push a group change? Background: our internal support structure will be redefined and users, that are actually in groups, have to move to other groups, to get other notifications.

Best regards

pstuerze

Created on Nov 14, 2014 12:29:56 PM



Votes:

0

Hello pstuerze,

With the current version of PRTG the user will need to login after you changed your Active Directory groups and the user will be automatically assigned to the new AD groups of PRTG. I'll forward your wish for a manual check to our feature request list for future versions of PRTG.

Best regards

Created on Nov 14, 2014 12:56:05 PM by  Felix Saure [Paessler Support]



Votes:

4

Any update on the manual check for AD group updates? Some of my users need to receive alerts but do not regularly login to the interface, so it would be very helpful if PRTG could accommodate changes to AD groups without requiring users to login. The ideal situation would be that PRTG periodically checks AD (e.g. daily) for updates to groups.

Created on May 21, 2018 4:37:15 PM



Votes:

0

No updates on that part I'm afraid. Too little demand for that. Sorry! :(


Kind regards,
Stephan Linke, Tech Support Team

Created on May 22, 2018 6:35:31 PM by  Stephan Linke [Paessler Support]



Votes:

8

I would like to see this feature. We have a number of groups where the underlying AD account has been removed but the user still shows up as a member of the group. I don't think it's a good solution to recommend we recreate the account and attempt to login in order to remove the user from the group.

Created on Jul 11, 2018 2:45:30 PM



Votes:

0

No other way as of now I'm afraid. For future reference, please use the vote button in the initial post in order to increase visibility for it. Thanks! :)


Kind regards,
Stephan Linke, Tech Support Team

Created on Jul 12, 2018 1:15:56 PM by  Stephan Linke [Paessler Support]



Votes:

13

Hello, I know Felix's comment is quite old, but if I correctly understand his last comment, I believe changes in AD group membership should be visible in PRTG after every login of a user, not only after the first login. Is this correct?

Currently I have removed an AD user from an AD group, but when this user logs in to PRTG no changes are made to his PRTG User Groups membership. Deleting the user and then logging in does make changes to PRTG User groups membership. It's impractical enough that a user needs to log on to register changes, but having to delete that user first is both impractical and extra work.

I can't vote yet to increase visibility for this topic, but I definitely feel AD synchronization should be included in PRTG.

Created on Aug 1, 2018 10:23:03 AM



Votes:

0

Didier,

Is your test user a direct member of the usergroup which you chose in PRTG, or is the user a member of another AD group and the membership is nested?

Best regards, Felix

Created on Aug 1, 2018 1:41:26 PM by  Felix Saure [Paessler Support]



Votes:

6

Hello Felix, the test user is a direct member of the usergroup. Some further tests showed that when I ADD a user to an AD group (that has a corresponding PRTG usergroup), and that user logs on in PRTG, then that user will be added to the PRTG usergroup. However, when I REMOVE that user from the AD group, and the user logs on in PRTG, the user is not removed from the PRTG usergroup.

Sufficient time was taken to prevent replication issues. The PRTG usergroup is not the primary group of the test user.

Best regards, Didier

Created on Aug 2, 2018 7:40:17 AM



Votes:

1

Hello Didier,

Your findings are correct here, PRTG won't automatically delete existing users. I'll take this with me if we discuss improvements for the AD implementation.

Best regards, Felix

Created on Aug 2, 2018 8:04:32 PM by  Felix Saure [Paessler Support]



Votes:

0

Hello Felix, just to be sure we understand each other correctly, I don't need PRTG to completely delete a user when I remove it from an AD group, I only want that user to be removed from the corresponding PRTG group. I suppose that is what you meant too, but I thought it was better to check.

Best regards, Didier

Created on Aug 3, 2018 8:35:56 AM



Votes:

0

Hi Didier,

That's what I understood, don't worry. :)

Best regards, Felix

Created on Aug 6, 2018 6:45:23 PM by  Felix Saure [Paessler Support]



Votes:

11

We also +1 for all manual AD polling for user and group profile updates. API forced polling as well.

Paessler should assume there is large support for such all such features related to interacting with Active Directory as we assumed that you would. We did not know you did NOT have it and were caught off guard (and in trouble) when we found out.

Add a toggle on and off for each polling feature -- giving full control to the prtg administrator is best.

Created on Aug 15, 2018 3:20:42 PM



Votes:

21

Another feature would be a synced user status: if I deactivate a User in AD (if staff leaves the company), it should get inactive in PRTG. Also we changed our company Domain Name, so that email adressses changed to. These changes are not propagated from AD to PRTG. We have to change each Email manually or delete the users, so that a new profile gets generated. But then we loose notification and security context mappings.

Created on Aug 17, 2018 11:21:05 AM



Votes:

0

Is this working yet? Is there a synchronization with AD and are the users removed in prtg from groups after they are removed from AD group?

Created on Oct 5, 2022 6:57:30 AM



Votes:

0

Hello ArSo,

No updates yet to the existing functionality. Please stay tuned on the Release Notes page of future version.


Kind regards,
Felix Saure, Tech Support Team

Created on Oct 5, 2022 9:23:43 AM by  Felix Saure [Paessler Support]



Votes:

0

Maybe you should update this line "If you change the group membership of an AD user, this change is only reflected in the respective user groups in PRTG if this AD user has logged in to PRTG again."

from https://www.paessler.com/manuals/prtg/active_directory_integration to match how it works at the moment

Created on Oct 6, 2022 9:48:24 AM



Votes:

0

Hello ArSo,

Thanks for the feedback. The lines relate to the update which is done if the user account itself is used for the authentication. This will then update the group status. So this still applies, there is not automatic update though, that's what it means.


Kind regards,
Felix Saure, Tech Support Team

Created on Oct 10, 2022 5:35:04 AM by  Felix Saure [Paessler Support]




Disclaimer: The information in the Paessler Knowledge Base comes without warranty of any kind. Use at your own risk. Before applying any instructions please exercise proper system administrator housekeeping. You must make sure that a proper backup of all your data is available.