I've never tried anything like that, myself; not a legacy app, nor a brand spanking new one. But I believe that CFLDAP would be in play, as that will access the Active Directory that the users exist in. As far as code changes, the only thing that would change, just off the top of my head, would be setting the variables that grant the roles, etc. Instead of being set by the result of a query, they would be set by whatever is returned in the CFLDAP results. But, then I'm not at all familiar with your legacy app.. this is an assumption. V/r, ^ _ ^ PS. Personally, just from a security standpoint, I would be using CFLDAP on every page load; that way, if a user is online using this app, and (for whatever reason) said user has a role taken away, then the change will be reflected in real time, not upon the next time the user logs on. Just my two cents.
... View more