Dynamic Group functionality within the Active Roles Administration Service is enabled by default.
There is some overhead associated with leaving this functionality enabled, notably there could be relatively expensive LDAP queries performed against Active Directory such as the following:
(&(objectCategory=CN=Group,CN=Schema,CN=Configuration,DC=domain,DC=com)(accountNameHistory=*[DG]*))
If Dynamic Groups are not leveraged in the environment, it may be desired to disable the feature in order to prevent any overhead.
© 2024 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center