It is possible to use an Active Roles Workflow to prevent the nesting of Groups within other Groups.
The below Workflow will interrupt such an operation and display an error message if any initiator attempts to add members to a Group and any of those members is a Group.
It is also possible to parse all of the members of a Group membership change and strip out only Groups while allowing other object types, but this is only possible using a custom scripted solution. For assistance with implementing a custom script, please contact Professional Services or One Identity Sales.
© ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center