AD can resolve users but not external groups

Article ID:217694137
1 minute readKnowledge base

Issue

  • Jenkins is able to resolve individual users from AD and can see external groups, but cannot resolve external group membership. For example, user1 is part of the Developer group. User1 can be added individually, and the Developer group appears to be resolved(shows external group icon in RBAC, for example). When assigning permissions to the Developer group, they are not reflected for its members, such as user1.

Environment

Resolution

Navigate to the AD plugin configuration under Manage Jenkins -> Configure Global Security. The option Remove irrelevant groups needs to be unchecked. This feature was added in Active Directory plugin version 1.39. It is incompatible with RBAC, as RBAC needs to see every group a user is a member of.