
24
Connection Broker should match the user’s entered login name against, for example:
CN: The user’s common name
sAMAccountName: The NT4 logon name
userPrincipalName: The user’s email address
uid: For OpenLDAP authentication servers, the user’s login ID
10. In the Other section, configure any additional options for this authentication server. The settings in
this section allow you to do the following
a. Query order: Sets the Position property of this authentication server. The Connection Broker
uses the position to determine the order in which it searches for users in your different
authentication servers.
b. Allow login with an expired password: Allows users with a valid, but expired, password to log
in into the Connection Broker and be assigned a desktop. The Windows GINA on the desktop
prompts the user to enter a new password.
c. Verbose error message for failed login: When selected, presents the user with a detailed
explanation if their login fails.
Active authentication server: Indicates that the Connection Broker should search this
authentication server for users.
d. Query for group information: This setting indicates if the Connection Broker automatically
loads group information from Active Directory. Loading group information can place a
significant load on the Connection Broker. If you have a large Active Directory structure,
uncheck this option. This example, however, assumes this option is selected.
This option will not appear when you subsequently edit the authentication server, To
change the setting for the Query for group information option after initially creating the
authentication server, go to the > Users > Assignments page associated with that
authentication server.
e. Notes: Optional notes for this authentication server.
11. Click Save.
Step 10: Assigning User Roles and Policies
Use the > Users > Assignments tab to assign roles and policies to users based on the user’s attributes and
location.
When a user logs in to the Connection Broker, the Connection Broker searches the authentication servers
defined on the > Users > Authentication Servers page, shown in the following figure, for a user that
matches those credentials.
Comentarios a estos manuales