Creating Dynamic Groups
Video Tutorial
In this video guide, you will learn in what scenarios you can use Dynamic Groups, how they work, and their basic configuration.
Active Directory Dynamic group configuration with two membership commands: AD Users, when group membership is controlled automatically, and AD members of this group, when the membership of the specified group is controlled manually.
Getting Started
Dynamic Groups begin with the selection of an existing group onto which the rules are applied to control the group's membership. Dynamic Groups do not create groups, they only populate the group according to the configured rules.
There are two types of Dynamic Groups: Active Directory and Office 365. Each Dynamic Group can have:
-
The following Membership rules:
Include Query - includes the set of objects that meet a certain condition.
Exclude Query - excludes the set of objects that meet a certain condition.
Include Objects - includes specific objects that meet a certain condition.
Exclude Objects - excludes specific objects that meet a certain condition.
Each Membership rule includes membership rule commands that define the type of included objects and the conditions these objects must meet. See the Membership Rule Commands for Active Directory and Microsoft 365 Dynamic Groups for Active Directory and Office 365 Dynamic Groups.
Creating a dynamic group
Open the Cayosoft Administrator Console.
-
Click NEW+ > Dynamic Group.
At the top of the object select dialog, select Extension (Active Directory or Microsoft Office 365) and the type of group to be populated. For example, the Active Directory extension is selected.
In the Name begins with field, enter the first few letters of the group's name, then click Search.
Select the group from the search results.
-
The new Dynamic Group appears and the Membership Rules can now be added.
If you create a Dynamic Group that is based on the Active Directory group, you can check Add change details to Change History and Execution History to track Dynamic Group changes and scope in the Auditing Cayosoft Administrator with Change History and Execution History.
Adding Membership Rules based on a user attribute value
-
Click Add Membership Rule.
In the Name field, enter a descriptive name for the rule.
Select the memberships type of Include Query or Exclude Query depending on which operation is going to be performed.
Click the Add button on the membership rule.
Select AD Users. The lower half of the dialog box now displays the query configuration.
Click the picker button to the right of the Query Criteria field.
Click Add Condition.
Enter the attribute name, condition operator, and value that must be met for the rule to include or exclude a user
Click OK. You will see your criteria show in the Query Criteria field.
Click OK.
Click Save Changes.
Click the Preview to verify the correct users are returned by the query.
Schedule the Dynamic GroupRule
In the Enforce/Schedule section click Enable.
From the options displayed, select the settings that will determine when you want to run the Dynamic Group's rule and update memberships
Click Save.
Creating a Runbook out of existing Dynamic Groups
When you need to run Dynamic Groups in a certain order and you don't want to configure schedules for each Dynamic Group separately, you can create a Runbook out of existing Dynamic groups:
In the Cayosoft Administrator Console, click on the New button on the top and select Runbook:
Provide a name and a folder for the Runbook.
Once it is created, select Link to existing from inside the Sequence section of the created Runbook:
Select the Dynamic Groups you want to include in this runbook.
Schedule Runbook as required.
Comments
0 comments
Please sign in to leave a comment.