# Migrating from Active Directory to local users

**URL:** <https://community.jenkins.io/t/migrating-from-active-directory-to-local-users/13504>\
**Category:** Ask a question\
**Created:** [March 20, 2024, 10:26am UTC](https://community.jenkins.io/t/migrating-from-active-directory-to-local-users/13504 "2024-03-20T10:26:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abyweinberg](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/abyweinberg/32/6642_2.png) [@Abyweinberg](https://community.jenkins.io/u/Abyweinberg)\
**Post date:** [March 20, 2024, 10:26am UTC](https://community.jenkins.io/t/migrating-from-active-directory-to-local-users/13504/1 "2024-03-20T10:26:09Z")

</div>

bs"d

> **Jenkins setup:**
>
> ```
> Jenkins: 2.426.2
> OS: Linux - 6.1.0-17-cloud-amd64
> Java: 17.0.9 - Eclipse Adoptium (OpenJDK 64-Bit Server VM)
> 
> ace-editor:1.1  
> active-directory:2.34  
> ant:497.v94e7d9fffa\_b\_9  
> antisamy-markup-formatter:162.v0e6ec0fcfcf6  
> apache-httpcomponents-client-4-api:4.5.14-208.v438351942757  
> authentication-tokens:1.53.v1c90fd9191a\_b\_  
> badge:1.9.1  
> bootstrap4-api:4.6.0-6  
> bootstrap5-api:5.3.2-3  
> bouncycastle-api:2.30.1.77-225.v26ea\_c9455fd9  
> branch-api:2.1144.v1425d1c3d5a\_7  
> build-blocker-plugin:1.7.9  
> build-timeout:1.32  
> caffeine-api:3.1.8-133.v17b\_1ff2e0599  
> checks-api:2.0.2  
> cloudbees-folder:6.858.v898218f3609d  
> command-launcher:107.v773860566e2e  
> commons-lang3-api:3.13.0-62.v7d18e55f51e2  
> commons-text-api:1.11.0-95.v22a\_d30ee5d36  
> credentials:1311.vcf0a\_900b\_37c2  
> credentials-binding:642.v737c34dea\_6c2  
> data-tables-api:1.13.8-2  
> display-url-api:2.200.vb\_9327d658781  
> docker-commons:439.va\_3cb\_0a\_6a\_fb\_29  
> docker-workflow:572.v950f58993843  
> durable-task:543.v262f6a\_803410  
> echarts-api:5.4.3-2  
> email-ext:2.103  
> font-awesome-api:6.5.1-1  
> git:5.2.1  
> git-client:4.6.0  
> git-server:99.va\_0826a\_b\_cdfa\_d  
> github:1.37.3.1  
> github-api:1.318-461.v7a\_c09c9fa\_d63  
> github-branch-source:1767.va\_7d01ea\_c7256  
> gradle:2.9  
> groovy-postbuild:228.vcdb\_cf7265066  
> gson-api:2.10.1-15.v0d99f670e0a\_7  
> handlebars:3.0.8  
> instance-identity:185.v303dc7c645f9  
> ionicons-api:56.v1b\_1c8c49374e  
> jackson2-api:2.16.1-373.ve709c6871598  
> jakarta-activation-api:2.0.1-3  
> jakarta-mail-api:2.0.1-3  
> javax-activation-api:1.2.0-6  
> javax-mail-api:1.6.2-9  
> jaxb:2.3.9-1  
> jdk-tool:73.vddf737284550  
> jjwt-api:0.11.5-77.v646c772fddb\_0  
> jquery-detached:1.2.1  
> jquery3-api:3.7.1-1  
> jsch:0.2.16-86.v42e010d9484b\_  
> json-path-api:2.8.0-21.v8b\_7dc8b\_1037b\_  
> junit:1256.v002534a\_5f33e  
> ldap:711.vb\_d1a\_491714dc  
> lockable-resources:1228.v1b\_2379444670  
> mailer:463.vedf8358e006b\_  
> mapdb-api:1.0.9-28.vf251ce40855d  
> matrix-auth:3.2.1  
> matrix-project:822.v01b\_8c85d16d2  
> mina-sshd-api-common:2.11.0-86.v836f585d47fa\_  
> mina-sshd-api-core:2.11.0-86.v836f585d47fa\_  
> momentjs:1.1.1  
> okhttp-api:4.11.0-157.v6852a\_a\_fa\_ec11  
> pam-auth:1.10  
> pipeline-build-step:540.vb\_e8849e1a\_b\_d8  
> pipeline-github-lib:42.v0739460cda\_c4  
> pipeline-graph-analysis:202.va\_d268e64deb\_3  
> pipeline-groovy-lib:689.veec561a\_dee13  
> pipeline-input-step:477.v339683a\_8d55e  
> pipeline-milestone-step:111.v449306f708b\_7  
> pipeline-model-api:2.2168.vf921b\_4e72c73  
> pipeline-model-declarative-agent:1.1.1  
> pipeline-model-definition:2.2168.vf921b\_4e72c73  
> pipeline-model-extensions:2.2168.vf921b\_4e72c73  
> pipeline-rest-api:2.34  
> pipeline-stage-step:305.ve96d0205c1c6  
> pipeline-stage-tags-metadata:2.2168.vf921b\_4e72c73  
> pipeline-stage-view:2.34  
> plain-credentials:143.v1b\_df8b\_d3b\_e48  
> plugin-usage-plugin:4.2  
> plugin-util-api:3.8.0  
> popper-api:1.16.1-3  
> popper2-api:2.11.6-4  
> resource-disposer:0.23  
> role-strategy:689.v731678c3e0eb\_  
> scm-api:683.vb\_16722fb\_b\_80b\_  
> script-security:1313.v7a\_6067dc7087  
> slack:684.v833089650554  
> snakeyaml-api:2.2-111.vc6598e30cc65  
> ssh:2.6.1  
> ssh-credentials:308.ve4497b\_ccd8f4  
> ssh-slaves:2.948.vb\_8050d697fec  
> sshd:3.322.v159e91f6a\_550  
> structs:325.vcb\_307d2a\_2782  
> subversion:2.17.3  
> timestamper:1.26  
> token-macro:400.v35420b\_922dcb\_  
> trilead-api:2.133.vfb\_8a\_7b\_9c5dd1  
> variant:60.v7290fc0eb\_b\_cd  
> windows-slaves:1.8.1  
> workflow-aggregator:596.v8c21c963d92d  
> workflow-api:1283.v99c10937efcb\_  
> workflow-basic-steps:1042.ve7b\_140c4a\_e0c  
> workflow-cps:3837.v305192405b\_c0  
> workflow-cps-global-lib:609.vd95673f149b\_b  
> workflow-durable-task-step:1313.vcb\_970b\_d2a\_fb\_3  
> workflow-job:1385.vb\_58b\_86ea\_fff1  
> workflow-multibranch:770.v1a\_d0708dd1f6  
> workflow-scm-step:415.v434365564324  
> workflow-step-api:639.v6eca\_cd8c04a\_a\_  
> workflow-support:865.v43e78cc44e0d  
> ws-cleanup:0.45
> ```

If I go to the URL `/manage/configureSecurity/`

The `Security Realm` is configured as `Active Directory`.  
I want to stop using the AD and manage the users’ credentials built in.

I’m afraid of breaking the system if I just disconnect the AD.

How can I migrate it?

---

<div class="post-metadata">

**Author:** ![mawinter69](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/mawinter69/32/1625_2.png) [@mawinter69](https://community.jenkins.io/u/mawinter69)\
**Post date:** [March 20, 2024, 12:18pm UTC](https://community.jenkins.io/t/migrating-from-active-directory-to-local-users/13504/2 "2024-03-20T12:18:13Z")

</div>

Try it out on a test instance and see what happens when you switch the security realm.

Take a backup before applying the change on your productive instance.

But you will most likely need to manually add all the users and set an initial password. The permissions are not affected by this change. So when you create the users and use the same userid as they had with AD, users will not see a difference except they now have an additional password for your Jenkins and no longer can use the domain password.  
Or you allow manual signup of users. But signup is a security risk as someone could just use a userid that is not yet registered but already has permissions from before.

One thing to consider:  
With the internal user database it is not possible to manage groups, so if you use groups from AD this will not work anymore. You will need to explicitly assign the permissions to your users.

---

<div class="post-metadata">

**Author:** ![Abyweinberg](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/abyweinberg/32/6642_2.png) [@Abyweinberg](https://community.jenkins.io/u/Abyweinberg)\
**Post date:** [March 20, 2024, 2:19pm UTC](https://community.jenkins.io/t/migrating-from-active-directory-to-local-users/13504/3 "2024-03-20T14:19:59Z")

</div>

> [@mawinter69](#):
>
> Try it out on a test instance and see what happens when you switch the security realm.

Hi @mawinter69, thanks,

Do you know how to start a server (I use docker compose) with all the jobs disabled?

---

<div class="post-metadata">

**Author:** ![mawinter69](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/mawinter69/32/1625_2.png) [@mawinter69](https://community.jenkins.io/u/mawinter69)\
**Post date:** [March 20, 2024, 5:58pm UTC](https://community.jenkins.io/t/migrating-from-active-directory-to-local-users/13504/4 "2024-03-20T17:58:04Z")

</div>

Just create a new jenkins and start it

Create a new empty directory /data/jenkins\_test  
Download the jenkins.war and put it in that directory  
export JENKINS\_HOME= /data/jenkins\_test  
run  
`java -jar /data/jenkins_test/jenkins.war`  
Jenkins will start on port 8080
