In some complex use-cases, it may be desired to create a Dynamic Group or Managed Unit which holds members which are filtered based on the attribute values of another object.
For example: create a Dynamic Group which holds users who have direct reports, but not if those direct reports have a certain attribute value.
Active Roles uses an LDAP query to build Dynamic Groups and Managed Units, and LDAP cannot filter one object based on attribute values of a another object.
Instead, the related object values can be abstracted into a something which can then be queried.
© 2024 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy Cookie Preference Center