# X-Pack Security 5.2.2 - Active Directory Global Group Limit?

**URL:** <https://discuss.elastic.co/t/x-pack-security-5-2-2-active-directory-global-group-limit/78568>\
**Category:** Elasticsearch\
**Created:** [March 14, 2017, 5:33pm UTC](https://discuss.elastic.co/t/x-pack-security-5-2-2-active-directory-global-group-limit/78568 "2017-03-14T17:33:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mick66](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@mick66](https://discuss.elastic.co/u/mick66)\
**Post date:** [March 14, 2017, 5:33pm UTC](https://discuss.elastic.co/t/x-pack-security-5-2-2-active-directory-global-group-limit/78568/1 "2017-03-14T17:33:26Z")

</div>

I have set up x-pack security and configured an Active Directory realm which is working fine for most of my users. I had an issue today whereby someone was not getting assigned any roles once they were authenticated.

I turned on debugging and noticed that the list of Active Directory groups that was being compared by the role mapping process only contained about half the groups that the user was actually a member of.

Could anyone advise if there is a limit on the number of groups returned by this process.

The DEBUG entry was:

`[DEBUG][o.e.x.s.a.s.DnRoleMapper] [Server] the roles [[default_index]], are mapped from these [active_directory] groups`

`DEBUG][o.e.x.s.a.s.DnRoleMapper] [Server] the roles [[]], are mapped from the user [CN=LastName\, FirstName,OU=test,OU=Accounts,DC=domain,DC=com] for realm [active_directory/active_directory]`

Thanks in advance

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 14, 2017, 7:20pm UTC](https://discuss.elastic.co/t/x-pack-security-5-2-2-active-directory-global-group-limit/78568/2 "2017-03-14T19:20:24Z")

</div>

How many groups are returned? Are the missing groups security groups?

---

<div class="post-metadata">

**Author:** ![mick66](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@mick66](https://discuss.elastic.co/u/mick66)\
**Post date:** [March 15, 2017, 9:10am UTC](https://discuss.elastic.co/t/x-pack-security-5-2-2-active-directory-global-group-limit/78568/3 "2017-03-15T09:10:02Z")

</div>

Hi Jay

The user in question is a member of 115 Security Global Groups, the process has checked against only 103 and unfortunately the one I used in my role\_mapping.yml file is not on the checked list.

Cheers

Mick

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 15, 2017, 1:19pm UTC](https://discuss.elastic.co/t/x-pack-security-5-2-2-active-directory-global-group-limit/78568/4 "2017-03-15T13:19:07Z")

</div>

Does this group exist in a different domain in the forest?

When running with debug logging there should be a log message `group SID to DN [{}] search filter: [{}]` that contains all of the SIDs returned by active directory. Can you check the number of SIDs in the filter?

---

<div class="post-metadata">

**Author:** ![mick66](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@mick66](https://discuss.elastic.co/u/mick66)\
**Post date:** [March 15, 2017, 2:54pm UTC](https://discuss.elastic.co/t/x-pack-security-5-2-2-active-directory-global-group-limit/78568/5 "2017-03-15T14:54:30Z")

</div>

The group is in the same domain as the user account.

The number of SIDs in the `group SID to DN [{}] search filter: [{}]` is different again as it returned 100 entries.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 15, 2017, 3:28pm UTC](https://discuss.elastic.co/t/x-pack-security-5-2-2-active-directory-global-group-limit/78568/6 "2017-03-15T15:28:27Z")

</div>

This is very odd; the values from the filter are taken directly from the active directory tokenGroups attribute. Additionally, the default AD maximum page size is 1000, which means the most results in a single result would be 1000, but it doesn't appear that you're hitting this limit unless your AD has a value lower than the default.

Would you be willing to share the elasticsearch logs? If you do not feel comfortable sharing publicly, we can work out a way to share privately.

---

<div class="post-metadata">

**Author:** ![mick66](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@mick66](https://discuss.elastic.co/u/mick66)\
**Post date:** [March 15, 2017, 3:44pm UTC](https://discuss.elastic.co/t/x-pack-security-5-2-2-active-directory-global-group-limit/78568/7 "2017-03-15T15:44:18Z")

</div>

Happy to share the logs in private

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2017, 3:44pm UTC](https://discuss.elastic.co/t/x-pack-security-5-2-2-active-directory-global-group-limit/78568/8 "2017-04-12T15:44:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
