Rolling back to AD from AD Federation Services

This article provides steps for a scenario where it is necessary to roll back to using AD/LDAP instead of AD Federation Services (AD FS).

The product prevents any domain from being authenticated by both AD and AD FS simultaneously. In the course of following the steps below, there is a period wherein Issuetrak will not authenticate via AD or AD FS. For this reason, we recommend that you have a Sys Admin account that uses Issuetrak authentication, to avoid a situation in which you cannot access your own site.

At a high level, this process will do the following in Issuetrak:

  1. Disable AD FS authentication for a domain of your choosing.
  2. Enable AD/LDAP authentication on the domain you disabled AD FS for.
  3. Perform a user import to update all of the user accounts to use AD/LDAP as their authentication method.

Steps:

  1. Sign into Issuetrak as a Sys Admin.
  2. Click the gear icon in the upper right > click on AD Federation Services beneath Identity Management.
  3. Click edit next to the domain that you want to switch to AD.
  4. Uncheck Active.
  5. Click Save.
  6. Along the right context menu, click List Providers beneath Active Directory.
  7. Click edit next to the domain that you want to activate AD for.
  8. Click Test Connection and ensure that Issuetrak will successfully communicate with the selected domain controller.
  9. Upon a successful connection test, check Active.
  10. Click Update.
  11. Along the right context menu, click Import Users.
  12. Complete these steps for each OU/Group that needs to be updated in Issuetrak:
    1. Select the Domain that you've switched to AD from the dropdown.
    2. Toggle either AD Group or AD OU.
    3. Click the Select [Group | OU] button and choose which block of users to import.
    4. Click Preview Import.
    5. If you are satisfied with the preview, click Process Import. If you aren't satisfied with the preview, then refine your selection in the steps above.
  13. Check several user accounts to confirm that their Authentication Type is set to "Active Directory".
  14. Confirm that you can sign into Issuetrak via AD.
  15. Confirm that other users can sign into Issuetrak via AD.

You have successfully rolled your domain back from AD FS to AD/LDAP authentication.