About this task
An LDAP query role is based on an LDAP query to
an external directory service. Any user or group that meets the requirements of
the query is a member of the role.
To create an LDAP query
role
Procedure
-
On the Common Directory Services page, click Roles.
-
Click
.
-
In the Role Name field, type the
name that you want to assign to the new role.
Valid role names can contain only letters, numbers, underscores, or space
characters.
-
From the Role Provider
drop-down list, select LDAP
Query Role Provider.
-
Click
Apply.
-
On the Roles page,
click the name of the newly created role, or click
and then click Edit.
-
In the Role Membership section:
-
In the LDAP Query field
type a valid LDAP query.
-
Select the Simple Query
option if the query in the LDAP Query field
contains simplified LDAP query syntax.
Note: Unless you are creating a complex LDAP query, the query syntax
can be cumbersome to use. With the Simple Query
option, the syntax is filled in for you. For example, to find
all persons whose manager has the user ID
abrown, the simple query syntax is manager=abrown.
-
Select a directory service from the
Directory
Service drop-down list.
-
In the Principal Type
list, choose whether the query searches for Users or
Groups.
-
Click Save.