Skip to content
DataMiner Dojo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Updates & Insights
  • Questions
  • Learning
    • E-learning Courses
    • Tutorials
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • YouTube Videos
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Agility
      • Learn more about Agile
        • Agile Webspace
        • Everything Agile
          • The Agile Manifesto
          • Best Practices
          • Retro Recipes
        • Methodologies
          • The Scrum Framework
          • Kanban
          • Extreme Programming
        • Roles
          • The Product Owner
          • The Agile Coach
          • The Quality & UX Coach (QX)
      • Book your Agile Fundamentals training
      • Book you Kanban workshop
    • >> Go to DataMiner Docs
  • DevOps
    • About the DevOps Program
    • Sign up for the DevOps Program
    • DataMiner DevOps Support
    • Feature Suggestions
  • Downloads
  • Swag Shop
  • PARTNERS
    • Business Partners
    • Technology Partners
  • Contact
    • Sales, Training & Certification
    • DataMiner Support
    • Global Feedback Survey
  • >> Go to dataminer.services

Users not being removed from groups

Solved87 views1 day agoLDAP synchornization Users/Groups
1
Carl Stanley [DevOps Advocate]151 2 days ago 2 Comments

Hi Dojo,

In our set up we have Azure AD groups which enable users to use SSO when connecting to that DM cluster. Once the Azure AD group has been added, we create a new group in Users / Groups with the same name and then through the LDAP settings in System Settings, the users that are part of that group are synced.

I'm carrying out user access reviews and I've removed people from the Azure AD group that should no longer have access, however they still show up in Cube when I look at that same group.

Is there a step I'm missing to keep these in sync?

Thanks!

Carl Stanley [DevOps Advocate] Selected answer as best 1 day ago
Miguel Obregon [SLC] [DevOps Catalyst] commented 2 days ago

Hi Carl,
Can you trigger manually the Windows scheduled task "Skyline DataMiner LDAP Resync" and verify that the groups were updated?

Carl Stanley [DevOps Advocate] commented 2 days ago

HI Miguel,

I found the scheduled task to be disabled, but I enabled it and ran it manually and it reported as completing successfully however the groups didn't update in cube.

1 Answer

  • Active
  • Voted
  • Newest
  • Oldest
2
Bert Buysschaert [SLC] [DevOps Advocate]5.06K Posted 1 day ago 2 Comments

Hi Carl,

You mention that you manually create a group with the same name in DataMiner. This procedure is what is used for automatic creation of users authenticated by Entra ID using SAML, see step 8. In this workflow, users only get added to that group the next time they login (or removed from groups they no longer are a member of).

If you want to import the users beforehand, you need to configure DataMiner to import users and groups from Microsoft Entra ID. By configuring the <AzureAD /> tag in DataMiner.xml, you can import a group from Azure with the "Add existing group..." button. In this workflow, you do not create an empty group with the same name.

Carl Stanley [DevOps Advocate] Selected answer as best 1 day ago
Carl Stanley [DevOps Advocate] commented 1 day ago

HI Bert,

That's right, we're using automatic creation of users using SAML and we have the Dataminer.xml configured correctly with the matching claims. So the users are created correctly when they log in, however when I remove a user from an Azure AD group, they still exist in Dataminer.

Do I have to manually go into Cube and remove them there as well or is there something else I'm missing?

Thanks!

Bert Buysschaert [SLC] [DevOps Advocate] commented 1 day ago

If you want them gone, you will indeed have to remove them manually.
DataMiner only gets updated with group membership at the moment that a user logs in, so if they will never login anymore, the user will remain displayed in that group.

Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas
Privacy Policy • Terms & Conditions • Contact

© 2026 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs

[ Placeholder content for popup link ] WordPress Download Manager - Best Download Management Plugin