Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 961839
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 16, 20262026-05-16T01:24:33+00:00 2026-05-16T01:24:33+00:00

A precursor: I’ve worked now in two enviroments with conflicting principals on this. I

  • 0

A precursor: I’ve worked now in two enviroments with conflicting principals on this. I am outlining the competing ideas and would like to know which is ‘correct’ given the scenario described.

Scenario: Multiple applications exist on our intranet. We are implementing OpenSSO with LDAP as our authentication control and user directory. The issue comes to play is, with the LDAP authentication we know a user is allowed on the intranet but to which applications is questionable.

We intend to use LDAP to control what applications each user can access i.e. helpdesk, consultant review, report generator, survey creator etc.

The question arises in that, within each application are a significant amount of roles, and the fact that people may have multiple roles.

What is the best way to address this second area? Shoudl ALL roles be in the ldap or just the application allowances with each app database containing the more granular roles?

  • 1 1 Answer
  • 1 View
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-16T01:24:34+00:00Added an answer on May 16, 2026 at 1:24 am

    One approach is to use LDAP to maintain relatively high-level role information, but keep the very detailed application-specific information internal to each application.

    For example, an individual might be members of LDAP groups (roles) like “employee”, “help desk associate”, “help desk supervisor”, etc., and then the individual applications would map the high-level roles into the application-specific functions. A particular high-level role might imply access to multiple applications, and different roles would have different levels of access.

    For example, a “help desk associate” might be able to create tickets, but maybe only a supervisor can delete them or run reports.

    This is one of those areas where there’s no one right answer. Centralizing everything in LDAP gives you better ability to report/audit individuals’ access, at the cost of complicating your central LDAP schema with a lot of application-specific data. Also, depending on what existing/commercial applications you’re trying to integrate, the applications may not support pulling all their fine-grained access information from LDAP.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have a few ideas I would like to try out in the Disk
I asked a precursor to this question here: Click link in DIV and show
I am trying to do something like this: for ( std::list< Cursor::Enum >::reverse_iterator i
I've got a very simple app where the flow looks like this: User reads
Originally this question and its precursor were asked on R-Sig-Geo: https://stat.ethz.ch/pipermail/r-sig-geo/2012-July/015648.html The mow.R contains:
This is a question I was wondering about for some time now, but couldn't
I have the following html form, which is generated dynamically: <ul class=precursorList> <li> Precursor
I've seen a few questions like the one I'll ask but nothing identical. I
I want to count the number of pages that would be produced if I
This is my table where i want my PNRNo to be generated as 'PNRRES001'

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.