Configuration of Family Groups
Family Groups automate the creation and maintenance of Active Directory groups based on user or computer attributes and organizational relationships.
For example, you can use Family Groups to create and maintain groups for departments, locations, or manager hierarchies. For manager-based groups, Cayosoft Administrator can create a group for each manager and automatically maintain group membership based on the users who report to that manager.
Family Groups can help automate common Active Directory group management scenarios that would otherwise require manual group creation and membership maintenance or custom automation.
When to use Family Groups
Use Family Groups when you need to automatically create and maintain multiple groups based on shared organizational data or relationships. A Family Groups rule evaluates a source set of users or computers, groups the objects by a selected property, and creates a group for each resulting value.
Family Groups are especially useful when the group structure itself needs to follow your organization. For example, you can create groups for each department, location, manager, or other property without creating and configuring each group individually.
Use Dynamic Groups when you need to automatically maintain the membership of an individual group based on membership rules. Use Family Groups when you need to automatically create and maintain a set, or family, of groups based on a common grouping property.
Common Family Groups scenarios
You can use Family Groups to automatically create and maintain groups based on how users or computers are organized in your environment.
Common scenarios include:
- Creating a group for each manager and maintaining membership based on the manager hierarchy.
- Creating groups based on organizational properties such as department or location.
- Creating groups based on a combination of multiple properties.
- Creating groups as a flat set or as a nested hierarchy.
For example, if you need to create groups for each manager, maintain groups for direct reports, include direct and indirect reports under a leader, or create groups that follow your organizational hierarchy, group users by the Manager property and use the Employees under manager membership rule.
This connects common organizational concepts such as employees under a manager, reporting relationships, and manager hierarchies to the corresponding Family Groups configuration in Cayosoft Administrator.
Configuring the Family Groups rule
You need to create and configure the Family Groups rule to start using Family Groups in your environment. The rule defines:
- Family and group settings: where the Active Directory groups should be created and what names these groups should have.
- The property the Active Directory users or computers should be grouped by.
How to create a Family Groups rule
NOTE: Family Groups can be created only on a Publisher service if the replication group is configured.
- In the Cayosoft Administrator Console, navigate to Home > Family Groups.
- Click New Family Group in the Actions menu or on the Home page in the Cayosoft Administrator Console, click +New in the upper-left corner and select Family Group.
- Select the source system that contains the objects to be grouped.
- Select the target system where the groups will be created.
- Select the type of groups that will be created.
- Click Next.
- Select the group-by property. One group is created for each unique value of this property.
- Click Next.
- Select the domain or Organizational Unit where the groups will be created.
- Click Finish.
For detailed Family Groups rule settings, see Family Groups rule (AD groups) Overview.
Scenario: Create groups for employees under each manager
Use this scenario when you want to create and automatically maintain an Active Directory distribution group for each manager based on your organizational hierarchy.
For example, an organization may need groups representing employees who report to individual managers. Instead of manually creating these groups and maintaining their membership as reporting relationships change, you can use a Family Groups rule based on the Manager property.
Example: Manager A is a manager of Manager B, who is a manager of Users A, B, and C. In this case, two groups are created: Group A for Manager A and Group B for Manager B. Group A contains Manager B. Group B contains Users A, B, and C.
Supported manager scenarios
Family Groups can represent a manager hierarchy in different ways depending on how you want users and groups to be organized.
For direct-report scenarios, you can create a group for each manager and populate it with users who report directly to that manager. For multi-level hierarchies, the Employees under manager membership rule can process additional levels of management, including all levels below the selected manager.
You can also choose how the resulting hierarchy is represented. With Nest hierarchical properties: No, Family Groups creates a flat set of manager-based groups. When hierarchical nesting is enabled, the resulting group structure can represent the relationships between levels of the management hierarchy.
For example, you can use this configuration to create groups for employees under each manager or to represent everyone below a particular leader in the organizational hierarchy, including indirect reports when multiple management levels are selected.
Manager hierarchy options
When configuring a manager-based Family Groups rule, consider how the management hierarchy should be represented.
The Employees under manager membership rule provides options for determining which levels of the management hierarchy are processed.
The Nest hierarchical properties setting controls whether groups based on hierarchical properties are created as a flat set or as a nested hierarchy.
The following configuration uses:
- Group by property - Organizational - by manager to create groups based on the Manager property.
- AD Users - Employees under manager Membership Rule Command to determine group membership.
- All levels of management for the management hierarchy.
- Nest hierarchical properties: No so that hierarchical properties are not represented as nested groups.
Create Family Groups rule
- In the Cayosoft Administrator Console, navigate to Home > Family Groups.
- Click New Family Group.
- Specify source and target systems as Active Directory.
- Select AD Distribution Group type.
- Click Next.
- Select Group by property - Organizational - by manager.
- Click Next.
- Specify Group Family name.
- Specify the Active Directory Organizational Unit where the groups will be created.
- Click Finish.
Configure Family Groups rule
| Setting name | Value |
|---|---|
| Family & Group Settings |
|
| Membership Rule |
|
| Output | Change Output type to Create and Save report. |
Result
After the Family Groups rule runs, Active Directory distribution groups Group A and Group B are created in the Organizational Unit specified in the Create groups in setting. Group A contains Manager B. Group B contains Users A, B, and C.
Considerations and limitations
Before configuring manager-based Family Groups, consider the following:
- Family Groups uses the Manager relationship in the source directory to determine the management hierarchy. Make sure Manager values are populated and maintained correctly for the users included in the rule.
- Decide whether the groups should represent direct reports only or multiple levels of the management hierarchy. Configure the Employees under manager membership rule accordingly.
- Decide whether the resulting groups should be created as a flat set or should represent the management hierarchy through nested groups. Use the Nest hierarchical properties setting to control this behavior.
- The selected group-by property determines which groups Family Groups creates. One group is created for each unique value processed by the rule.
- Changes to source data, including Manager relationships and the selected group-by property, can affect the groups and membership produced the next time the Family Groups rule runs.
Change History
| Version | Notes |
|---|---|
| 11.2.0 | The AD Computers command has been added. |
Comments
0 comments
Please sign in to leave a comment.