# Active Directory authentication for groups

**URL:** <https://forums.suse.com/t/active-directory-authentication-for-groups/2580>\
**Category:** Rancher 1.x\
**Created:** [April 23, 2016, 3:02pm UTC](https://forums.suse.com/t/active-directory-authentication-for-groups/2580 "2016-04-23T15:02:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fernando\_Felicissimo](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@Fernando\_Felicissimo](https://forums.suse.com/u/Fernando_Felicissimo)\
**Post date:** [April 23, 2016, 3:02pm UTC](https://forums.suse.com/t/active-directory-authentication-for-groups/2580/1 "2016-04-23T15:02:59Z")

</div>

I joined my Active Directory with Ranger and the way that all valid users in Active Directory can access the console Rancher I would like to leave configured so that only one group can authenticate to the Rancher is possible to do this?

tks,

Fernando Felicissimo

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [April 23, 2016, 10:02pm UTC](https://forums.suse.com/t/active-directory-authentication-for-groups/2580/2 "2016-04-23T22:02:30Z")

</div>

Currently, everyone would have access to the Rancher instance, but they would not have access to your [environment](http://docs.rancher.com/rancher/configuration/environments/) and you can restrict to environments.

If someone logs into Rancher and are not invited into Rancher, they are automatically created a default personal environment.

---

<div class="post-metadata">

**Author:** ![Fernando\_Felicissimo](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@Fernando\_Felicissimo](https://forums.suse.com/u/Fernando_Felicissimo)\
**Post date:** [April 25, 2016, 2:12pm UTC](https://forums.suse.com/t/active-directory-authentication-for-groups/2580/3 "2016-04-25T14:12:22Z")

</div>

Hi Denise,

Ok … so I did a good practice since I have several development teams would be to create an environment for team?

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [April 25, 2016, 4:33pm UTC](https://forums.suse.com/t/active-directory-authentication-for-groups/2580/4 "2016-04-25T16:33:53Z")

</div>

Yes, if each team will be using different resources (i.e. hosts), then you could create different environments for each team and provide them access to each of their teams.

---

<div class="post-metadata">

**Author:** ![Fernando\_Felicissimo](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@Fernando\_Felicissimo](https://forums.suse.com/u/Fernando_Felicissimo)\
**Post date:** [April 25, 2016, 5:42pm UTC](https://forums.suse.com/t/active-directory-authentication-for-groups/2580/5 "2016-04-25T17:42:25Z")

</div>

> [@denise](#):
>
> Yes, if each team will be using different resources (i.e. hosts), then you could create different environments for each team and provide them access to each of their teams.

Hi Denise,

If developers will access the same hosts … I thought about doing this targeting team to prevent developers see the containers from other teams, that is, the developer only vera containers of your specific team .

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [April 25, 2016, 5:57pm UTC](https://forums.suse.com/t/active-directory-authentication-for-groups/2580/6 "2016-04-25T17:57:30Z")

</div>

If you are looking to have developers to share the same hosts, then they will need to have access to the same environments and they will be able to see containers from other teams.

It sounds as if you want your teams to not be able to see containers of other teams, which requires separate environments and therefore separate hosts.
