You are viewing limited content. For full access, please sign in.

Question

Question

Is there a way to have Directory Services synchronize Named Users with a nested AD Group?

asked on March 30, 2016

A client of ours has the need to synchronize with a series of nested AD groups. Synchronization with a single group works fine, but not a nested group. See attached image. The intended functionality would be that you select a group, and it synchronizes with all subgroups under that group. In this case I have about 75 subgroups two layers down.

Is this intended, or a feature request?

 

1 0

Replies

replied on April 11, 2016

Helpful bump!

0 0
replied on April 11, 2016

Are you on the initial release of Directory Server, with no patches (9.2.0.453)? If so, your issue should be resolved by applying the patch in KB:1013586 (or any later patch or update). 

0 0
replied on April 13, 2016 Show version history

We're actually on the very latest version of Directory Services, hotfix and all. However, this patch note leads me to believe that nested groups should be supported, so I will pursue this through the Support process.

0 0
replied on April 5, 2017 Show version history

Hi Gareth,

 

How did you get on with this? I'm seeing interesting results when trying to sync a group with nested groups, especially if the users are part of more than 1 of the nested groups....

 

Edit - Also it would be good to know if LFDS supports nested groups within a root group which also contain nested groups.

0 0
replied on April 5, 2017

We do support nested groups within nested groups. If you are encountering problems using nested groups, or "interesting results", it would be great to hear more detail, as they work for our active directory.

0 0
replied on April 5, 2017

Thanks Brianna, good to know it's supported. The issue I'm having is the customer is removing the user from one of the groups within a group, the sync is running but the user's license is not being changed from "full" to "none".

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.