SharePoint By Yagya Shree

SharePoint | MOSS: Unable to Add Administrative groups [AD] to Single Sign On Service

leave a comment »

PROBLEM:
———-
àYou are trying to configure a Single Sign-On using a security group which is inside a active directory on the SharePoint Server

àWhenever you are specifying the Group name in the Central administration–operations–Manage Settings for Single Sign-On–Manager Server Settings–Enterprise Application Definition Administrator Account and adding a group named “<Domainname>\<AD group name>” getting error message

“Invalid input values. Please enter a valid account in the form of domain\group or domain user.”

àYou are unable to add the group
RESOLUTION:
———–
àchecked the issue and found that if we use the “Group Scope” as “Domain Local” the AD group does not get resolved in the SSO configuration

àIt is also true if we use “Group Type” as “Distribution”

àWe created a new AD group using following settings:

Group Scope:  Global
Group Type: Security

àUsed the group to configure SSO and it worked

More Information:

Understanding User and Group Accounts
<http://technet.microsoft.com/en-us/library/bb726978.aspx>

Lesson 9: Clustering the Master Secret Server
<http://msdn.microsoft.com/en-us/library/cc558968.aspx>

Specifying Single Sign-On Administrators and Affiliate Administrators Accounts
<http://msdn.microsoft.com/en-us/library/aa771094.aspx>

Single Sign-on Services for Microsoft Enterprise Application
download.microsoft.com/download/c/6/5/c65ff9fd-0ed7-47f6-91ab-000e6265ea5b/enterprise_sso_whitepaper.doc

Keyword: Sharepoint MOSS Signle Sign-On SSO AD group

Advertisements

Written by Yagyashree

May 1, 2009 at 6:30 pm

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: