Configuration of Group Publishing
Users that have permissions to Self-Service > My AD Memberships web query and to My Cloud Memberships web query web queries can use these queries to see their membership in Active Directory and Microsoft 365 groups and add themselves to the published groups. They can either see all the Active Directory groups which they are members of or only those Active Directory groups that are published for discovery. Both Active Directory and Microsoft 365 groups can be published for self-service requests and discovery during the Configuration of Restricted Groups rule.
Publishing Active Directory and Microsoft 365 group
Both Active Directory and Microsoft 365 groups can be published for discovery and self-service. Publishing a group allows people to join and leave this group in Cayosoft Self-Service. Please read the Configuration of Restricted Groups rule article on how to do this.
Active Directory groups can also be published using Membership Approval web action. Please see the Membership Approval article for details.
NOTE: A published group can be configured to require the owner's approval for membership changes. If group owner approval is required, then a user request to join this group is forwarded to the group owner(s) for approval. The user is notified with an Approval is required message box. They can track his request status in the My Request Status web query.
Configuration of My AD Memberships web query
The My AD Memberships web query displays a list of Active Directory groups that a Web Portal user is a member of.
You can configure Cayosoft Administrator to display all Active Directory groups that a user is a member of or only published groups. To configure this behavior, open Cayosoft Administrator Console, navigate to My AD Memberships web query and specify the Show groups setting.
For more information about the web query settings, please see My AD Memberships web query article.
Limitation of My AD Memberships web query scope
When you want users to be able to see their membership only in certain Active Directory groups, you can limit My AD Memberships web query scope:
In the Cayosoft Administrator console, navigate to Configuration > Web Portal > Virtual Admin Units > My Organization > My AD Memberships.
Browse for the Action and Picker Scopes section.
-
In the Additional scope(s) for object selection, specify Distinguished Names of OUs that contain groups that will be displayed in My AD Memberships web query:
Copy{"OU=myOU,DC=cayo,DC=com;OU=myOU2,DC=cayo,DC=com"} Click Save changes.
Learn more in: My AD Memberships web query.
Limitation of Discover Groups scope
When you want users to be able to see only certain published Active Directory groups, you can limit the Discover Groups scope:
In the Cayosoft Administrator console, navigate to Configuration > Web Portal > Virtual Admin Units > Object Pickers > Discover Groups.
In the Additional scope(s) for object selection, specify Distinguished Names of OUs that contain groups that will be displayed in the Discover Groups form:
{"OU=myOU,DC=cayo,DC=com;OU=myOU2,DC=cayo,DC=com"}-
Click Save changes.
NOTE: There are no such settings for the My Cloud Memberships web query.
Comments
0 comments
Please sign in to leave a comment.