What are the steps to assign an Active Directory Security group to newly created user accounts (ADSAccounts)?
The requirement is that new users receive the group membership, and the Active Directory account in the target has the group membership as well.
In the scenario described below, new Identities may be assigned an account definition that in turn creates the associated ADSAccount; or Active Directory (AD) user accounts may be imported from the target system via a synchronization which creates Identity objects if none exist, or assign the ADSAccount to already existing Identities. The end result should be that the AD users receive the group membership dynamically (automatically) via inheritance.




© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center