Skip to content

LDAP Filters #52141

Answered by jvirot
jvirot asked this question in Q&A
Feb 13, 2025 · 3 comments · 3 replies
Discussion options

You must be logged in to vote

Ok finaly i find the solution.
The problem was identation of filters and label atrributes.
we must ident those fields like base_dn and not like discovery
like this:

        -----END CERTIFICATE-----

  discovery:
    base_dn: "*"
    filters:
      ##- '(!(primaryGroupID=516))' # exclude domain controllers
    # (optional) LDAP attributes to convert into Teleport labels.
    # The key of the label will be "ldap/" + the value of the attribute.
    - '(&(objectClass=organizationalUnit)(|(ou:dn:=Harden_T0)(ou:dn:=Domain Controllers)))'
    label_attributes:
    - location
    - operatingSystem

on the docs online is

windows_desktop_service:
  enabled: yes
  discovery:
    base_dn: '*'
  fil…

Replies: 3 comments 3 replies

Comment options

You must be logged in to vote
1 reply
@jvirot
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@webvictim
Comment options

@jvirot
Comment options

Answer selected by webvictim
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants