This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

using Windows Authentication for Orion users

This is probably a really stupid question, but I will ask it still.  Is there a way to setup new users in Orion so that it uses their Windows creditials?  In my previous job we had an older version of Orion and when I would setup new users the way I was told was for the username to be "domain name/username" and NO password.  When I would do this, the user would go to the orion website and they automatically were granted access to the page.

I'm now in a new job and we just purchased Orion 9.5.  I just finished setting it up this morning and I'm trying to get used to the new look, but also when I tried to add a new user it seems now that I'm forced to enter a password.

Does anyone here know the best practice to setup users so they don't have to enter all their creditials it just uses their windows login creditials?

Thanks,
Bill

  • FormerMember
    0 FormerMember

    here is an additional question on this same subject... 

    once you have the ad passthru working ( i do not have this working yet mind...)  how about the scenario with multiple active directory domains

    i have DOM1, and DOM2.

    all users of Orion are members of DOM1, but the orion servers are members of DOM2.  I am setting up a one-way trust in the domain so members in DOM1 have access to all resources in DOM2, so authentication can pass DOWN but not UP

    how will this work in Orion, do i have to wait for AD integration?

    (In case u ask why i have 2 domains, it is because DOM2 is customer facing, and DOM1 is internal, next to the corporate firewalls)

    cheers

    dan

  • I have asked the same thing before.

    Have you done these steps? 

         

        NT Windows Authentication
        1. Click Start > Control Panel > Administrative Tools > Internet Information Services (IIS) Manager.
        2. Expand Internet Information Services > Local Computer > Web Sites in the left pane.
        3. Select SolarWinds NetPerfMon.
        4. Click Action > Properties.
        5. Click the Directory Security tab.
        6. Click Edit within the Authentication and access control area.
        7. Clear Enable anonymous access.
        8. Check Integrated Windows authentication in the Authenticated access group.
        9. Click OK to close the Authentication Methods window.
        10. Click Apply, if available, and then click OK to close the SolarWinds NetPerfMon Properties window.
        11. Close the IIS Manager.
        12. Click Start > All Programs > SolarWinds Orion > Configuration and Auto-Discovery > Configuration Wizard, check Website, and then click
        Configuring Automatic Login 291
        through the Configuration Wizard to enable IIS NT security for Windows Pass-through Security.
        13. If you want to add accounts in the Orion Web Console Account Manager using NT Domain Authentication Format, enter accounts in Domain\UserID format, as follows:
        •Washington\Edward
        •StLouis\Everyone
        Note: Currently, the only domain group supported by the Orion Web Console is the ‘Everyone’ group. For more information about using Account Manager, see “Creating New Accounts” on page 63.
        14. If you want to add accounts using Local Computer Authentication Format, enter accounts in Computer\UserID format, as follows:
        •SolarWindsS2\Edward
        •Server3\JonesR

      1. The only thing I'm not finding is the following:

        12. Click Start > All Programs > SolarWinds Orion > Configuration and Auto-Discovery > Configuration Wizard, check Website, and then click
        Configuring Automatic Login 291
        through the Configuration Wizard to enable IIS NT security for Windows Pass-through Security.

        I'm using v9.5 and when I go through these steps I don't see any prompt regarding Configuring Automatic Login.

      2. Have you reviewed page 305 of the Admin guide, which can be found here

      3. For several versions we have been required to put in a password in order to create a domain account within Orion.  When I configure the new account I use the "domain\username" format and put the number "1" as the password and confirm it.   The account is created then under the account settings I select "change password" then leave both fields blank and click submit.  That then clears the password in the Orion user database and AD will be queried.

         
      4. Stoned,
        That was the perfect answer.  I was thinking I missed something in the setup that would allow me to setup accounts and NOT require the password so AD passthrough would work.  I tried your tip and just changed the password afterward to empty and it worked!
        Thanks,
        Bill

      5. You are welcome, and I am glad to be able to help.

         

         

        ~David