Sorry for the late reply. I already tinker many things on the Shiro configuration (omitting or adding quote, removing OUs, changing searchbase), but none has successfully resolve my issue.
I already search the web, one person seems to be having the same issue, but no solution on that. https://stackoverflow.com/questions/40644145/apache-zeppelin-ad-ldap-realm Right now my temporary solution is having two simultaneous realms, IniRealm and ActiveDirectoryGroupRealm. ActiveDirectoryGroupRealm handles official credentials, and IniRealm handles small static admin credential. Is there anyone who have same issue as me? -- View this message in context: http://apache-zeppelin-users-incubating-mailing-list.75479.x6.nabble.com/Active-Directory-do-not-mapped-roles-correctly-tp5989p5996.html Sent from the Apache Zeppelin Users (incubating) mailing list mailing list archive at Nabble.com.