Validity of group memberships
There are different assignments to groups possible depending on the construction of the domain structure and the domain trusts. You can find more exact information about permitted group memberships in the documentation for your Windows Server.
Ensure the following if you want to map group memberships using forests:
In the following tables, the groups, user accounts, contacts, and computers permitted in One Identity Manager listed in groups.
Legend for the tables:
-
G = Global
-
U = Universal
-
L = Local
Table 49: Group memberships permitted within a domain
Distribution |
Global |
x |
|
|
x |
|
|
x |
x |
x |
Universal |
x |
x |
|
x |
x |
|
x |
x |
x |
Local |
x |
x |
x |
x |
x |
x |
x |
x |
x |
Security |
Global |
x |
|
|
x |
|
|
x |
x |
x |
Universal |
x |
x |
|
x |
x |
|
x |
x |
x |
Local |
x |
x |
x |
x |
x |
x |
x |
x |
x |
Table 50: Group memberships permitted within a hierarchical domain structure
Distribution |
Global |
|
|
|
|
|
|
|
x |
|
Universal |
x |
x |
|
x |
x |
|
x |
x |
x |
Local |
x |
x |
|
x |
x |
|
x |
x |
x |
Security |
Global |
|
|
|
|
|
|
|
|
|
Universal |
x |
x |
|
x |
x |
|
x |
x |
x |
Local |
x |
x |
|
x |
x |
|
x |
x |
x |
Table 51: Group memberships permitted within a forest
Distribution |
Global |
|
|
|
|
|
|
|
|
|
Universal |
|
|
|
|
|
|
|
|
|
Local |
x |
x |
|
x |
x |
|
x |
|
x |
Security |
Global |
|
|
|
|
|
|
|
|
|
Universal |
|
|
|
|
|
|
|
|
|
Local |
x |
x |
|
x |
x |
|
x |
|
x |
Table 52: Group memberships permitted between forests
Distribution |
Global |
|
|
|
|
|
|
|
|
|
Universal |
|
|
|
|
|
|
|
|
|
Local |
x |
x |
|
x |
x |
|
x |
|
x |
Security |
Global |
|
|
|
|
|
|
|
|
|
Universal |
|
|
|
|
|
|
|
|
|
Local |
x |
x |
|
x |
x |
|
x |
|
x |
Related topics
Adding Active Directory groups to Active Directory groups
Use this task to add a group to another group. This means that the groups can be hierarchically structured.
To assign groups directly to a group as members
-
In the Manager, select the Active Directory > Groups category.
-
Select the group in the result list.
-
Select the Assign groups category.
-
Select the Has members tab.
-
Assign child groups in Add assignments.
TIP: In the Remove assignments pane, you can remove the assignment of groups.
To remove an assignment
- Save the changes.
To add a group as a member of other groups
-
In the Manager, select the Active Directory > Groups category.
-
Select the group in the result list.
-
Select the Assign groups task.
-
Select the Is member of tab.
-
In the Add assignments pane, assign parent groups.
TIP: In the Remove assignments pane, you can remove the assignment of groups.
To remove an assignment
- Save the changes.
Related topics
Assigning Active Directory account policies to Active Directory groups
For domains from the functional level Windows Server 2008 R2 and above, it is possible to define additional password policies in addition to the default password policies. This allows individual users and groups to be subjected to stricter account policies as intended for global groups.
To specify account policies for a group
-
In the Manager, select the Active Directory > Groups category.
-
Select the group in the result list.
-
Select the Assign account policies task.
-
In the Add assignments pane, assign account policies.
TIP: In the Remove assignments pane, you can remove account policy assignments.
To remove an assignment
- Save the changes.
Related topics
Assigning secretaries to Active Directory groups
Assign a secretary to the group. The secretary is displayed in the email recipient’s properties in Microsoft Outlook.
To assign a secretary to a group
-
In the Manager, select the Active Directory > Groups category.
-
Select the group in the result list.
-
Select the Assign secretaries task.
-
Select the table which contains the user from the Table menu at the top of the form. You have the following options:
-
In the Add assignments pane, assign secretaries.
TIP: In the Remove assignments pane, you can remove assigned secretaries.
To remove an assignment
- Save the changes.