With the Active Roles console, you can export groups to an XML file and then import them from that file to populate a container in a different domain. The export and import operations provide a way to relocate groups between domains.
To export groups, select them, right-click the selection, and select All Tasks | Export. In the Export Objects dialog box, specify the file where you want to save the data, and click Save.
To import groups, right-click the container where you want to place the groups, and then click Import. In the Import Directory Objects dialog box, select the file to which the groups were exported, and click Open.
To delete groups, select them, right-click the selection, and click Delete. Then, click Yes to confirm the deletion. If you select multiple groups, clicking Delete displays the Delete Objects dialog box. To delete all the selected groups, select the Apply to all items check box, and then click Yes.
|NOTE: Deleting a group is an irreversible operation. A new group with the same name as a deleted group does not automatically assume the permissions and memberships of the deleted group. When recreating a deleted group, you need to manually add all permissions and memberships. |
Active Roles provides the ability to deprovision rather than delete groups. Deprovisioning a groups refers to a set of actions that are performed by Active Roles in order to prevent the use of the group.
The Deprovision command on a group updates the group object in Active Directory as prescribed by the deprovisioning policies. Active Roles comes with a default policy to automate some commonly-used deprovisioning tasks, and allows the administrator to configure and apply additional policies.