<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Directory Roles - Administrators in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755511#M28640</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;You will need to re-configure your web-adaptor to recongnize the shared key that you provided when you chose to authenticate at the web-tier.&amp;nbsp; Can you login to the web-server (where IIS is running) and access this page in a browser: &lt;A href="http://localhost/arcgis/webadaptor"&gt;http://localhost/arcgis/webadaptor&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Rember that the 'Administrator Username' is the Primary administrator user (not the service account that was created on the local box or in your existing AD).&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;If you've lost the shared key you can re look that up by going to the rest page: &lt;A href="http://localhost:6080/arcgis/admin/security/config"&gt;http://localhost:6080/arcgis/admin/security/config&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You will be prompted for credentials and you can use your primary site administrator if you havn't disabled it yet.&lt;BR /&gt;&lt;BR /&gt;Hopefully that will help out.&amp;nbsp; I've spent the past week mucking with different security models and have had very very poor performance when using the 'web tier' for authentication.&amp;nbsp; See another thread I've started here: &lt;A href="http://forums.arcgis.com/threads/61813-Intermittent-slow-performance-accessing-rest-page"&gt;http://forums.arcgis.com/threads/61813-Intermittent-slow-performance-accessing-rest-page&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I would be interested in knowing if you have similar performance issues once you get your web tier authentication working properly.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;HTH&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am not sure the web adapter configuration is an issue as I had it set to web tier when using the arcgis role store and am using now that i switched to AD. I also used the exact same password when I changed it. However I will give it a try just in case.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;GIS setup is much simpler than yours so I am not sure how much I will be able to help in the way of performance but I would be glad to share my experience once I am up and running.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Jul 2012 19:02:31 GMT</pubDate>
    <dc:creator>BrianLeroux</dc:creator>
    <dc:date>2012-07-10T19:02:31Z</dc:date>
    <item>
      <title>Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755507#M28636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I am trying to set up my initial roles in 10.1 using an Active Directory role store. I logged in as the PSA and serched for a AD group that I am in and gave it Administrative rights. I log out of manager and try to log in with my domain account and get "You must enter an account that is a member of either the Administrator or Publisher roles for this site." I tried using domain\UserName with the same result. I also tried giving this role access to the entire site. Any Ideas why I can't log into manager using an AD Role?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Additional info:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ArcGIS Server 10.1, IIS 7, &amp;amp; Web Adaptor all installed on same server. I have the default services running and can set security on the services using Active Directory Roles.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 17:34:51 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755507#M28636</guid>
      <dc:creator>BrianLeroux</dc:creator>
      <dc:date>2012-07-10T17:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755508#M28637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;What is handling the authentication?&amp;nbsp; Is it set to 'web tier' or 'GIS server'?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Did you configure the user/role store for 'Windows Domain' or 'LDAP'?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Did you change any authentication paramaters on the IIS-&amp;gt;Default Web Site-&amp;gt;arcgis (like disabling anonymous and enabling windows authentication)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Also - did you configure the web-adaptor after you configured security in the GIS 'site'?&amp;nbsp; If so did you check the box allowing users to manage the site through the web-adaptor?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Some of those answers might help solve your problem.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 18:26:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755508#M28637</guid>
      <dc:creator>PF1</dc:creator>
      <dc:date>2012-07-10T18:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755509#M28638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks for the reply.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I am using the Web Tier Authentication.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The User/Role Store is set to Windows Domain.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I made the following changes on IIS. I wasn't able to access any service until I made these changes:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; - Disable Anonymous access to the 'arcgis' virtual directory&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; - Enable Windows Authentication in the 'arcgis' virtual directory&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; - Move 'NTLM' to the top of the list or Providers&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; - Restart IIS&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I did configure the web adapter after we set up security on the GIS Site. I did this while I was using an ArcGIS role store. After switching to AD I no longer have access to the Web Adaptor. I get a 403 Forbidden Access. It seams like this is happening because the server thinks I am not an Admin anymore. I did allow management through the web adaptor.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 18:39:05 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755509#M28638</guid>
      <dc:creator>BrianLeroux</dc:creator>
      <dc:date>2012-07-10T18:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755510#M28639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Thanks for the reply.&lt;BR /&gt;I am using the Web Tier Authentication.&lt;BR /&gt;&lt;BR /&gt;The User/Role Store is set to Windows Domain.&lt;BR /&gt;&lt;BR /&gt;I made the following changes on IIS. I wasn't able to access any service until I made these changes:&lt;BR /&gt; - Disable Anonymous access to the 'arcgis' virtual directory&lt;BR /&gt; - Enable Windows Authentication in the 'arcgis' virtual directory&lt;BR /&gt; - Move 'NTLM' to the top of the list or Providers&lt;BR /&gt; - Restart IIS&lt;BR /&gt;&lt;BR /&gt;I did configure the web adapter after we set up security on the GIS Site. I did this while I was using an ArcGIS role store. After switching to AD I no longer have access to the Web Adaptor. I get a 403 Forbidden Access. It seams like this is happening because the server thinks I am not an Admin anymore. I did allow management through the web adaptor.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You will need to re-configure your web-adaptor to recongnize the shared key that you provided when you chose to authenticate at the web-tier.&amp;nbsp; Can you login to the web-server (where IIS is running) and access this page in a browser: &lt;/SPAN&gt;&lt;A href="http://localhost/arcgis/webadaptor"&gt;http://localhost/arcgis/webadaptor&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Rember that the 'Administrator Username' is the Primary administrator user (not the service account that was created on the local box or in your existing AD).&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you've lost the shared key you can re look that up by going to the rest page: &lt;/SPAN&gt;&lt;A href="http://localhost:6080/arcgis/admin/security/config"&gt;http://localhost:6080/arcgis/admin/security/config&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You will be prompted for credentials and you can use your primary site administrator if you havn't disabled it yet.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hopefully that will help out.&amp;nbsp; I've spent the past week mucking with different security models and have had very very poor performance when using the 'web tier' for authentication.&amp;nbsp; See another thread I've started here: &lt;/SPAN&gt;&lt;A href="http://forums.arcgis.com/threads/61813-Intermittent-slow-performance-accessing-rest-page"&gt;http://forums.arcgis.com/threads/61813-Intermittent-slow-performance-accessing-rest-page&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would be interested in knowing if you have similar performance issues once you get your web tier authentication working properly.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;HTH&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 18:53:49 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755510#M28639</guid>
      <dc:creator>PF1</dc:creator>
      <dc:date>2012-07-10T18:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755511#M28640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;You will need to re-configure your web-adaptor to recongnize the shared key that you provided when you chose to authenticate at the web-tier.&amp;nbsp; Can you login to the web-server (where IIS is running) and access this page in a browser: &lt;A href="http://localhost/arcgis/webadaptor"&gt;http://localhost/arcgis/webadaptor&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Rember that the 'Administrator Username' is the Primary administrator user (not the service account that was created on the local box or in your existing AD).&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;If you've lost the shared key you can re look that up by going to the rest page: &lt;A href="http://localhost:6080/arcgis/admin/security/config"&gt;http://localhost:6080/arcgis/admin/security/config&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You will be prompted for credentials and you can use your primary site administrator if you havn't disabled it yet.&lt;BR /&gt;&lt;BR /&gt;Hopefully that will help out.&amp;nbsp; I've spent the past week mucking with different security models and have had very very poor performance when using the 'web tier' for authentication.&amp;nbsp; See another thread I've started here: &lt;A href="http://forums.arcgis.com/threads/61813-Intermittent-slow-performance-accessing-rest-page"&gt;http://forums.arcgis.com/threads/61813-Intermittent-slow-performance-accessing-rest-page&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I would be interested in knowing if you have similar performance issues once you get your web tier authentication working properly.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;HTH&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am not sure the web adapter configuration is an issue as I had it set to web tier when using the arcgis role store and am using now that i switched to AD. I also used the exact same password when I changed it. However I will give it a try just in case.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;GIS setup is much simpler than yours so I am not sure how much I will be able to help in the way of performance but I would be glad to share my experience once I am up and running.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 19:02:31 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755511#M28640</guid>
      <dc:creator>BrianLeroux</dc:creator>
      <dc:date>2012-07-10T19:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755512#M28641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I reconfigued the web adaptor and still no luck. As it stands when I am set to use users &amp;amp; Roles from Windows Active Directory I am not able to log in to manager with a domain account after making a AD group Admins on the GIS server. I have tried going through the web adaptor and directy to the server at port 6080. Any other suggestions are appreciated.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Update- When using ArGIS Admin Users - Security - Get Privileges I enter my user name and is shows me only as having ACCESS and not Administer even know I made a AD group I am in an Administrative group. When I check Privileges on the group I am in it shows the Access level as Administer. Stumped...&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 11:40:33 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755512#M28641</guid>
      <dc:creator>BrianLeroux</dc:creator>
      <dc:date>2012-07-11T11:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755513#M28642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Well I have made some progress diagnosing the issue. I was able to succesfully log into ArcGIS Server Manasger with one of my windows domain accounts. The domain account that worked is only a part of 4 groups none of which are within nested groups. My account that does not work is in groups that are nested. When I look at how many groups that I am ultimately part of it, is around 130. This leadsme to belive ArcGIS Server has a probelm with nested groups or it has a limit on how many groups a user can be part of. Anyone else having similar issues?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2012 17:33:53 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755513#M28642</guid>
      <dc:creator>BrianLeroux</dc:creator>
      <dc:date>2012-07-16T17:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755514#M28643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Well I have made some progress diagnosing the issue. I was able to succesfully log into ArcGIS Server Manasger with one of my windows domain accounts. The domain account that worked is only a part of 4 groups none of which are within nested groups. My account that does not work is in groups that are nested. When I look at how many groups that I am ultimately part of it, is around 130. This leadsme to belive ArcGIS Server has a probelm with nested groups or it has a limit on how many groups a user can be part of. Anyone else having similar issues?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I can confirm this issue for us.&amp;nbsp; We are using Windows user/role store with GIS Server authentication.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;UL&gt;&lt;BR /&gt;&lt;LI&gt;My 1 of my AD accounts work just fine (who is an administrator, and in less than 5 AD groups).&amp;nbsp; &lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;One of my other AD accounts is splattered in 15-20 AD groups and is also part of sub-groups.&amp;nbsp; I was going to use my second account as a publisher to test that functionality.&amp;nbsp; &lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;I added one of my co-workers who is part of many many many AD groups (with sub-groups) and it taks over 5 minutes to do anything through manager&lt;/LI&gt;&lt;BR /&gt;&lt;/UL&gt;&lt;SPAN&gt;We attributed this to the 'publisher role' originally, thinking that is what was slowing it down.&amp;nbsp; I added his account (and my second account) to the administrators role and it is still awfully slow.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We added the AD service account as a publisher and it runs very fast.&amp;nbsp; We also changed that account to be an administrator and it also runs very fast!&amp;nbsp; This account is not part of any AD roles at the moment (and was only added to the 1 role when trying it as a publisher or administrator).&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would agree that there seems to be a major performance issue when traversing a large AD tree where users are in many groups and there are sub-groups involved.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The good news: we found a great fix that we like better so far.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We've now configured the security of the site the following: &lt;/SPAN&gt;&lt;BR /&gt;&lt;UL&gt;&lt;BR /&gt;&lt;LI&gt;User Store: Windows Domain&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Role Store: ArcGIS Server Built-in&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Auth. Tier: GIS Server&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Auth. Mode: ArcGIS Tokens&lt;/LI&gt;&lt;BR /&gt;&lt;/UL&gt;&lt;BR /&gt;&lt;SPAN&gt;So far this seems to have solved our performance issues as both a user consuming the services (anonymous) and as either a publisher or administrator.&amp;nbsp; This also allows us to control our groups/roles without having to involve the operational IT staff that have control over AD so I think this will work better than having the role store in the windows domain.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm wondering if this is also why we experienced slow performance issues when doing web-tier authentication as I've described here: &lt;/SPAN&gt;&lt;A href="http://forums.arcgis.com/threads/61813-Intermittent-slow-performance-accessing-rest-page"&gt;http://forums.arcgis.com/threads/61813-Intermittent-slow-performance-accessing-rest-page&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I might try to re-configure the site to do web-tier authentication, but leave the role store with the ArcGIS Server Built-in.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 22:06:01 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755514#M28643</guid>
      <dc:creator>PF1</dc:creator>
      <dc:date>2012-07-17T22:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755515#M28644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;I can confirm this issue for us.&amp;nbsp; We are using Windows user/role store with GIS Server authentication.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;&lt;UL&gt;&lt;BR /&gt;&lt;LI&gt;My 1 of my AD accounts work just fine (who is an administrator, and in less than 5 AD groups).&amp;nbsp; &lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;One of my other AD accounts is splattered in 15-20 AD groups and is also part of sub-groups.&amp;nbsp; I was going to use my second account as a publisher to test that functionality.&amp;nbsp; &lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;I added one of my co-workers who is part of many many many AD groups (with sub-groups) and it taks over 5 minutes to do anything through manager&lt;/LI&gt;&lt;BR /&gt;&lt;/UL&gt;We attributed this to the 'publisher role' originally, thinking that is what was slowing it down.&amp;nbsp; I added his account (and my second account) to the administrators role and it is still awfully slow.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;We added the AD service account as a publisher and it runs very fast.&amp;nbsp; We also changed that account to be an administrator and it also runs very fast!&amp;nbsp; This account is not part of any AD roles at the moment (and was only added to the 1 role when trying it as a publisher or administrator).&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;I would agree that there seems to be a major performance issue when traversing a large AD tree where users are in many groups and there are sub-groups involved.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;The good news: we found a great fix that we like better so far.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;We've now configured the security of the site the following: &lt;BR /&gt;&lt;UL&gt;&lt;BR /&gt;&lt;LI&gt;User Store: Windows Domain&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Role Store: ArcGIS Server Built-in&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Auth. Tier: GIS Server&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Auth. Mode: ArcGIS Tokens&lt;/LI&gt;&lt;BR /&gt;&lt;/UL&gt;&lt;BR /&gt;So far this seems to have solved our performance issues as both a user consuming the services (anonymous) and as either a publisher or administrator.&amp;nbsp; This also allows us to control our groups/roles without having to involve the operational IT staff that have control over AD so I think this will work better than having the role store in the windows domain.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;I'm wondering if this is also why we experienced slow performance issues when doing web-tier authentication as I've described here: &lt;A href="http://forums.arcgis.com/threads/61813-Intermittent-slow-performance-accessing-rest-page"&gt;http://forums.arcgis.com/threads/61813-Intermittent-slow-performance-accessing-rest-page&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I might try to re-configure the site to do web-tier authentication, but leave the role store with the ArcGIS Server Built-in.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for the info Patrick. Our initial configuration was using the Windows Domain for users and ArcGIS Built-In Role Store with Web Tier authentication. The performance was good but I wasn't doing much besides logging in and configuring ther server.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Unfortunately, this configuration did not meet my requirements as far as user maintenance is concerned. I need a config that would allow/revoke user access when they are added/removed to a group in AD. We will have over 1,500 users that change on a continuous basis and it would be a lot of effort to manage manually. Alos, our IT department wants full control over user access for auditing reasons. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have a support ticket open with ESRI and they are researching the issue. If there is no resolution by next week I will discuss with ESRI during the UC next week.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 11:29:52 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755515#M28644</guid>
      <dc:creator>BrianLeroux</dc:creator>
      <dc:date>2012-07-18T11:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755516#M28645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Mr. Leroux,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have analogous user maintenance requirements.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Did opening your support ticket get any help toward resolving the issue with traversing complex &amp;amp; nest AD groups?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This is two months after your post and based on what I'm experiencing and reading about, ArcGIS Server 10.1 with AD/integrated security "is not" ready for "prime-time"...&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any thoughts?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;JT&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 19:40:52 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755516#M28645</guid>
      <dc:creator>troyturcott</dc:creator>
      <dc:date>2012-09-12T19:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755517#M28646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;JT-&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I am still working with ESRI to resolve my issue. We have made some progress in the troubleshooting process but have not pinned down a solution to my issue. Our "normal" AD users are created by a provisioning job and that seems to be the root cause of the issue. I was able to verify this by duplicating my account to create a test account which all of the same permissions. This new test account allows me to admin the server while my regular account that was created with our provisioning jobs will not. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So to you question, is ArcGIS Server 10.1 with AD/integrated security ready for "prime-time"?, I can't honest say yes or no until I find the cause of my issues. I can say that I do not have any issues with user security at the service level and Administration works fine when using an account that does not use our provisioning process. Once I get this issue resolved I will definately post back here with more details.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2012 15:32:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755517#M28646</guid>
      <dc:creator>BrianLeroux</dc:creator>
      <dc:date>2012-09-13T15:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755518#M28647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Brian,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Did you ever resolve this issue with Esri?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Jon.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 13:40:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755518#M28647</guid>
      <dc:creator>JonathanBailey</dc:creator>
      <dc:date>2013-02-13T13:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755519#M28648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Yes. It turns out there was an existing bug in 10.1 that did not allow a comma in a users full name. This was fixed in SP1.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 15:02:00 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755519#M28648</guid>
      <dc:creator>BrianLeroux</dc:creator>
      <dc:date>2013-02-13T15:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755520#M28649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Yes. It turns out there was an existing bug in 10.1 that did not allow a comma in a users full name. This was fixed in SP1.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Did you have performance issues when using AD Groups before SP1?&amp;nbsp; Wondering if that solved our performance issues with AD groups/roles.&amp;nbsp; We had major performance impacts with users that were either in many AD groups or nested (sub) groups.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 16:05:14 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755520#M28649</guid>
      <dc:creator>PF1</dc:creator>
      <dc:date>2013-02-13T16:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755521#M28650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Did you have performance issues when using AD Groups before SP1?&amp;nbsp; Wondering if that solved our performance issues with AD groups/roles.&amp;nbsp; We had major performance impacts with users that were either in many AD groups or nested (sub) groups.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Yes i had performance issues before SP1 but they persisted through the service pack upgrade. it turned out that the account apply the configuration settings was a user account that was a part of many nested groups casuing a major slowdown in the authentication process. We switched the domain account the server runs as which is only part of a very small amount of groups. The performance after making that change was significantly better.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 19:13:49 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755521#M28650</guid>
      <dc:creator>BrianLeroux</dc:creator>
      <dc:date>2013-02-13T19:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755522#M28651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;We have been experiencing similar issues for a while.. We have currently installed 10.1 on a Test Server but plan to roll it into production to replace our existing 10.0 ArcGIS Server by the month of May. But I guess we aren't making the deadlines because of the performance issues..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Local browsing to 10.1 Services whether with ArcCatalog or with IE is pretty fast on the Server itself, however as soon as you go to a client machine and pass the intranet + the Company Active Directory Groups, the performance is agonizingly slow.. And this is only while browsing through the ArcGIS Server Folder/Directories, direct URL's to any of our map services work just fine within out client applications..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We have been working with ESRI Tech Support for the last two weeks, but nothing productive has come up yet. Any suggestions here?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Muneer Majid&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Spatial &amp;amp; GIS Analyst&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Chevron Energy Technology Company&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Mar 2013 14:18:19 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755522#M28651</guid>
      <dc:creator>MuneerMajid</dc:creator>
      <dc:date>2013-03-07T14:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755523#M28652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Muneer,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We still have permormance issues but at this point it is limited to when we are managing the server. Publishing and updating services from ArcMap is very slow. Also connecting to Server Manager is very slow. However, performance is not an issue for us when consuming serivces in our Web Maps or ArcMap. Also browsing the srvices directory is fine.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We initially had perfomance issues that was resolved by changing the the domain account used to configure the server security. We initally used an admin's personal account which was a part of many nested groups. Changing this to the domain group used by the server sped things up considerably and is most likely because the number of groups this account is a memeber of is very limited (&amp;lt;5).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Mar 2013 15:32:33 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755523#M28652</guid>
      <dc:creator>BrianLeroux</dc:creator>
      <dc:date>2013-03-07T15:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755524#M28653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks for the information Brian..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We pretty much have the same issues that you are experiencing.. Additionally, browsing the directories is also very slow for us.. We are also using a domain Service Account and that one isnt a part of a number of nested groups.. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We just finished another working sessions with ESRI Tech Support, and we tried out a number of suggestions one of which was Enabling the Kernel Mode but nothing really has helped so far.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Mar 2013 18:51:30 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755524#M28653</guid>
      <dc:creator>MuneerMajid</dc:creator>
      <dc:date>2013-03-07T18:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755525#M28654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;We have been experiencing similar issues for a while.. We have currently installed 10.1 on a Test Server but plan to roll it into production to replace our existing 10.0 ArcGIS Server by the month of May. But I guess we aren't making the deadlines because of the performance issues..&lt;BR /&gt;&lt;BR /&gt;Local browsing to 10.1 Services whether with ArcCatalog or with IE is pretty fast on the Server itself, however as soon as you go to a client machine and pass the intranet + the Company Active Directory Groups, the performance is agonizingly slow.. And this is only while browsing through the ArcGIS Server Folder/Directories, direct URL's to any of our map services work just fine within out client applications..&lt;BR /&gt;&lt;BR /&gt;We have been working with ESRI Tech Support for the last two weeks, but nothing productive has come up yet. Any suggestions here?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Muneer Majid&lt;BR /&gt;Spatial &amp;amp; GIS Analyst&lt;BR /&gt;Chevron Energy Technology Company&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;What is your config setting for user and role store? Built in or windows domain? Or hybrid?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Mar 2013 19:36:34 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755525#M28654</guid>
      <dc:creator>PF1</dc:creator>
      <dc:date>2013-03-09T19:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Roles - Administrators</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755526#M28655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Pat,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We have been using Windows Domain all along.. We did try switching to Build in which worked relatively faster, but we cannot use that security model on our Production Domain.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;-Muneer&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2013 14:09:13 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/active-directory-roles-administrators/m-p/755526#M28655</guid>
      <dc:creator>MuneerMajid</dc:creator>
      <dc:date>2013-03-11T14:09:13Z</dc:date>
    </item>
  </channel>
</rss>

