Active Directory Authentication, cannot find CN=Organizational-Role

Hey folks, Im trying to follow the procedure for allowing AD logins for openstack. I have setup a samba 4 AD DC on CentOS, I was hoping to authenticate Openstack logins through this. This is a college project, nothing production related, so a single basic user login through this method would suffice.

There is no “CN=Organizational-Role” to open. I have successfully bound a server to my new domain. So I know it is working as far as I can tell, any ideas, please see screen cap attached in the link.


  1. In ADSI Edit go to schema

  2. Open CN=Organizational-Role

  3. In attribute editor edit possSuperiors

  4. Add groupOfNames in the values and click OK


Which guide are you following? It is much easier to use AD for Identity and SQL for assignment. Then you aren't making changes against the directory to allow for tenants/roles.

Hey, I was using this (

If you get stuck on anything, this is actually helpful as well:

Nice one, cheers pal :)

The issue has been resolved, after I ran the 5 years of windows 2008 r2 updates :-p Organizational-Role is now visible

