Rule description
This rule queries the specified text file data source that is in comma-separated variable format (CSV) and uses the names within the file to update the membership of groups specified in te rule. Names in the file must exactly match either the UserPrincipalName or the SamAccountName of a user, group, or mail for a contact that exists in Active Directory. This rule does not add or remove computer objects.
When to use this rule
Use this rule when you need to perform group membership update from HR/ERP/SIS system into Active Directory.
This rule requires a source text file in the comma-separated variable format (CSV). You can use the template CSV file provided with the rule, or create a file in Microsoft Excel and export it as CSV.
To use a template CSV file:
- In the Query section, click the [...] button next to the Select Data Source setting
-
Open Templates folder
-
Select AD Users Template CSV file
-
Click Open
The Query's source text file requires the following CSV (comma-separated value) format:
Member
joe@domain.com
kelly@domain.com
Rule Settings
Query Section
Setting name | Description |
---|---|
Limit scope to this domain or OU |
This setting defines the search query scope. To improve query performance, limit the scope to specific OU. Important: To test rule configuration, limit the rule scope to an OU that contains test accounts or objects.
|
Groups | Specify Active Directory group distinguishedNames. |
File with members |
Specifies the text file to be imported. The […] button allows the user to browse for the file and the Create/Edit button allows the creation or editing of the existing file in the built-in Data Source editor. |
Get members from this CSV column | Specify the column name from the CSV file to get the members. |
Attributes that used for search objects in AD |
Specify the attribute in the Active Directory to which the Data Source anchor attribute is to be compared. You can add users, groups, or contacts. Possible anchor attributes: samAccountName, userPrincipalName, or mail. This rule does not add or remove computer objects |
More Options |
|
Returned group properties |
To display additional properties for each object found by the query, add those properties to the list. |
Sort by |
Sort result objects list. |
Action Section
Setting name | Description |
---|---|
Action |
Specify the action to perform:
|
Output Section
This section defines the output format of this rule.
To get more information about this section, please see the Output section article.
Enforce/Schedule section
This section defines the schedule for how often to run the rule.
To get more information about this section, please see the Enforce/Schedule section article.
Comments
0 comments
Please sign in to leave a comment.