# DEFAULT\_USER\_IS\_RESTRICTED not working with LDAP-Auth?

**URL:** <https://forum.gitea.com/t/default-user-is-restricted-not-working-with-ldap-auth/6368>\
**Category:** General\
**Created:** [December 6, 2022, 12:48pm UTC](https://forum.gitea.com/t/default-user-is-restricted-not-working-with-ldap-auth/6368 "2022-12-06T12:48:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rschmidt](https://avatars.discourse-cdn.com/v4/letter/r/ce73a5/32.png) [@rschmidt](https://forum.gitea.com/u/rschmidt)\
**Post date:** [December 6, 2022, 12:48pm UTC](https://forum.gitea.com/t/default-user-is-restricted-not-working-with-ldap-auth/6368/1 "2022-12-06T12:48:19Z")

</div>

In my app.ini i configured

```auto
[service]
DEFAULT_USER_IS_RESTRICTED = true
DEFAULT_ALLOW_CREATE_ORGANIZATION = false

```

Authentification is done by LDAP. So if an new User logs in for the first time, a gitea-user is created, but he has not restricted rights. The DEFAULT\_ALLOW\_CREATE\_ORGANIZATION does work as expected (new users can not create organisations). So what am i doing wrong, or what do i not understand?

---

<div class="post-metadata">

**Author:** ![jake](https://avatars.discourse-cdn.com/v4/letter/j/f475e1/32.png) [@jake](https://forum.gitea.com/u/jake)\
**Post date:** [December 26, 2022, 8:39pm UTC](https://forum.gitea.com/t/default-user-is-restricted-not-working-with-ldap-auth/6368/2 "2022-12-26T20:39:14Z")

</div>

You are doing everything correctly, it appears that `DEFAULT_USER_IS_RESTRICTED` only applies when a user is signing up through the signup page and does not get applied when a user is created by the LDAP system. You should file a bug on GitHub for this: [Issues · go-gitea/gitea · GitHub](https://github.com/go-gitea/gitea/issues)
