# Migrating from local authentication to Active Directory?

**URL:** <https://forums.suse.com/t/migrating-from-local-authentication-to-active-directory/2826>\
**Category:** Rancher 1.x\
**Created:** [May 18, 2016, 12:38am UTC](https://forums.suse.com/t/migrating-from-local-authentication-to-active-directory/2826 "2016-05-18T00:38:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![andyshinn](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/andyshinn/32/442_2.png) [@andyshinn](https://forums.suse.com/u/andyshinn)\
**Post date:** [May 18, 2016, 12:38am UTC](https://forums.suse.com/t/migrating-from-local-authentication-to-active-directory/2826/1 "2016-05-18T00:38:41Z")

</div>

Is it possible to migrate from local authentication to Active Directory?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [May 18, 2016, 1:34am UTC](https://forums.suse.com/t/migrating-from-local-authentication-to-active-directory/2826/2 "2016-05-18T01:34:23Z")

</div>

You can turn auth off and then re-enable it with AD, but there is nothing to update the old local account entries to tie them to AD users.

That can be done manually/in the API by going through `/v1/accounts?kind=admin` and `/v1/accounts?kind=user`, changing on each account:

- the `externalIdType` to `ldap_user`
- the `externalId` to the DN of the user, e.g. `CN=Vincent,CN=Users,DC=mycompany,DC=com`

(I’d take a database backup first…)
