This procedure describes how to add Domain users to be used as login into the Automation Engine Pilot.
To get Domain users working in the Pilot,
BGSYSTEM user must be able to retrieve the following information of the Pilot users from the domain controller:
If Windows domain users are to be granted access to Automation Engine Pilot functionality, they must be added to the BGUSERS or BGADMIN (administrator for the Pilot) Windows group.
To add a Windows domain user to the BGUSERS group, perform the following steps:
You cannot add Domain groups in the BGUSERS and BGADMIN groups.
Before Automation Engine 12.1 if you log in with domain suffix, you can connect but will not have access rights. Checking the Users panel shows that the user is not logged in.
Since Automation Engine 12.1, you can login with a domain suffix.
If there are users from another domain as the Automation Engine,
The Firewall must be open to the domain trust:
135/TCP/udp RPC Endpoint Mapper
636/TCP LDAP SSL
If you set debugging on LogonServer and when you log in, you get a message that the user is not in the BGUSERS or BGADMIN group.
On the Active Directory Server:
Active Directory Users and Computers: Go to View and enable the Advanced Features option.
User settings, security settings, Authenticated Users must have Read access.
It's also possible that some domain users are working and others aren't because they have different security settings.
It is better to add, but the domain users that must be used for the Automation Engine Pilot in one group and change the security settings for this group.
The bgmd log file has the message:
LogonServer 22 Nov 11:30:44.423 - Logon:failed SetCurrentUser (Exception of class BG_EThreadLogonTypeNotGranted
Reason: The domain controller is resetting the local policies after some time
Following users must be present:
Note: This is an anonymous survey. If you need help from Esko Support, register a Support Case here.