jenkinsci / jenkinsci/active-directory-plugin

[JENKINS-73055] User is unable to have read access after using AD group as an authentication

Open
#657 0 comments 0 reactions 0 assignees View on GitHub
component:active-directory-plugin imported-jira-issue priority:major resolution:unresolved
Dominant language
Java
Stars
53
Forks
115
PR merge metrics
No merged PRs in 30d

Description

Hi I am using Active Directory as an authentication to Jenkins for users. I am adding two different domains. One of the domain is same as the Jenkins host machine domain. 

I am using Role-Based Strategy for Authorization. I am using AD group under roles and assigning overall read permission to Jenkins to this AD group. But users are facing error showing Access Denied user is missing Overall/Read permission.

Above mentioned case is happening for Domain 2 which is different from Jenkins host machine domain, though same has been working fine for user with same domain as of Jenkins host machine.

---
Originally reported by manglarobin, imported from: User is unable to have read access after using AD group as an authentication


  • assignee: fbelzunc
  • status: Open
  • priority: Major
  • component(s): active-directory-plugin
  • resolution: Unresolved
  • votes: 0
  • watchers: 1
  • imported: 2025-12-07

Raw content of original issue

Hi I am using Active Directory as an authentication to Jenkins for users. I am adding two different domains. One of the domain is same as the Jenkins host machine domain. 

I am using Role-Based Strategy for Authorization. I am using AD group under roles and assigning overall read permission to Jenkins to this AD group. But users are facing error showing Access Denied user is missing Overall/Read permission.

Above mentioned case is happening for Domain 2 which is different from Jenkins host machine domain, though same has been working fine for user with same domain as of Jenkins host machine.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the two-domain Active Directory configuration described in the issue and inspect the plugin's authentication and group-resolution behavior. Done means users from the second domain receive the assigned Overall/Read permission through their AD group, matching users from the Jenkins host domain.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authentication
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.