Grant AD user same rights as local admin user
-
- First post
- Posts: 1
- Joined: Mon Feb 27, 2017 9:18 pm
Re: Grant AD user same rights as local admin user
Hello,
A number of years ago we purchased a TS-559 Pro+ unit and inquired about the ability to perform web administration of the device with a domain user.
At that time, we were told that the feature was unavailable, but we did put in a feature request at that time.
We recently purchased a TS-853A unit, and even with the major advances in the UI of the web interface, it remains impossible to administer the unit with a domain account.
I re-inquired about this capability with our new purchase and received the following response:
"No, unfortunately it is not possible to allow domain users to have administrative capabilities for the NAS, only a local user (set in Administrator Group) are able to have such access.
This feature has already been requested and is being analysed for possible implementation, but cannot be guaranteed that will be really implemented.
I would like to thank you for your information and request for feature request, we really appreciate that."
A number of years ago we purchased a TS-559 Pro+ unit and inquired about the ability to perform web administration of the device with a domain user.
At that time, we were told that the feature was unavailable, but we did put in a feature request at that time.
We recently purchased a TS-853A unit, and even with the major advances in the UI of the web interface, it remains impossible to administer the unit with a domain account.
I re-inquired about this capability with our new purchase and received the following response:
"No, unfortunately it is not possible to allow domain users to have administrative capabilities for the NAS, only a local user (set in Administrator Group) are able to have such access.
This feature has already been requested and is being analysed for possible implementation, but cannot be guaranteed that will be really implemented.
I would like to thank you for your information and request for feature request, we really appreciate that."
-
- Starting out
- Posts: 24
- Joined: Sat Jan 16, 2016 7:48 pm
Re: Grant AD user same rights as local admin user
So maybe is just a way to say "if need work from us, then is surely no". Is not hard to implement because just now is working but it need to be done by commands, so it's not hard to implement a way to make it on the web interface. Just ask the domain for the users and add the users you wish to local groups...
-
- New here
- Posts: 3
- Joined: Thu Oct 06, 2016 1:58 pm
Re: Grant AD user same rights as local admin user
Did the usermod am able to login to the web interface with the AD account, but not SSH. Has anyone gotten that working?
-
- First post
- Posts: 1
- Joined: Wed Aug 29, 2018 9:37 am
Re: Grant AD user same rights as local admin user
I've just deployed a QNAP in our office and can't believe that AD users cannot administer a QNAP as standard.
If QNAP are serious about entering the enterprise environment then they need to enable management by AD accounts. I deployed one QNAP as a POC as it has all the file sharing features that I require, but I will not deploy a second unless they enable management by Active Directory and more specifically AD groups.
I did use the usermod command mentioned by Danixu86 in a post in 2016 and this has enabled logins to specified AD users, but this is not a long term solution.
For these commands worked for me (case sensitive)
Add new user
usermod -a -G administrators DOMAIN\\user
List admins
grep ^administrators /etc/group
Remove user
deluser --remove-home DOMAIN\\user
If QNAP are serious about entering the enterprise environment then they need to enable management by AD accounts. I deployed one QNAP as a POC as it has all the file sharing features that I require, but I will not deploy a second unless they enable management by Active Directory and more specifically AD groups.
I did use the usermod command mentioned by Danixu86 in a post in 2016 and this has enabled logins to specified AD users, but this is not a long term solution.
For these commands worked for me (case sensitive)
Add new user
usermod -a -G administrators DOMAIN\\user
List admins
grep ^administrators /etc/group
Remove user
deluser --remove-home DOMAIN\\user
- dolbyman
- Guru
- Posts: 35268
- Joined: Sat Feb 12, 2011 2:11 am
- Location: Vancouver BC , Canada
Re: Grant AD user same rights as local admin user
complain via ticket..complaining here will not fix anything (we are just users)
-
- First post
- Posts: 1
- Joined: Wed Aug 29, 2018 1:40 pm
Re: Grant AD user same rights as local admin user
DIR
277/5000
I am desperately desperate for the urgent help I have TS TES-1885U-D1521-8GR
I need to use QES due to deduplication - QES 2,0
The client requires logging into the administration panel of the AD domain account
the script?
alternative?
how to deliver it
any ideas ?
277/5000
I am desperately desperate for the urgent help I have TS TES-1885U-D1521-8GR
I need to use QES due to deduplication - QES 2,0
The client requires logging into the administration panel of the AD domain account
the script?
alternative?
how to deliver it
any ideas ?
-
- Starting out
- Posts: 20
- Joined: Sun Jul 08, 2018 5:25 am
Re: Grant AD user same rights as local admin user
Thank you for posting this question, as I've just setup my first QNAP NAS (TVS-1282), joined it to my domain, and spent a little time trying to figure out how to add a domain account to the Administrators Group on the TVS-1282... Not finding a way to do so, I landed here an a search of the forums... only to find out, this feature apparently still is not available. I'll head over to the QNAP helpdesk to inquire.... as everyone else apparently has done so...
regards,
sjtsnix
regards,
sjtsnix
-
- First post
- Posts: 1
- Joined: Mon Sep 03, 2018 5:24 am
- dolbyman
- Guru
- Posts: 35268
- Joined: Sat Feb 12, 2011 2:11 am
- Location: Vancouver BC , Canada
Re: Grant AD user same rights as local admin user
if no feature requests are opened .. nothing will ever change .. QNAP does not come here
-
- First post
- Posts: 1
- Joined: Fri Oct 30, 2020 1:47 am
Re: Grant AD user same rights as local admin user
had the same issue. looked around the UI forever until i basically found the solution myself and happened upon this thread.
don't understand why this isnt a feature. wouldnt be hard to implement.
don't understand why this isnt a feature. wouldnt be hard to implement.
-
- Experience counts
- Posts: 1543
- Joined: Tue Dec 18, 2012 9:29 am
- Contact:
Re: Grant AD user same rights as local admin user
Well, I left the company in 2013 so...
It would seem that the people who took up this job after me, don't really care too much.