AD Users - Employees under manager Membership Rule Command
This membership rule command updates the Active Directory Dynamiс Group membership with employees' accounts who have a manager with the specified DistingushedName attribute.
NOTE: AD Users - Employees under manager command uses a Global Catalog search. You can filter only by the attributes that are included in the Global Catalog. User this article to check if the Active Directory attribute is in Global Catalog: All Attributes - Win32 apps | Microsoft Docs.
NOTE: The employees are filtered out from results if their manager doesn't satisfy the Query Criteria or Filter. To find all employees on all levels and then apply a filter on all found users, review these step-by-step instructions: How to configure Active Directory Dynamic Group to find all employees who report to the manager.
Membership Rule Command Settings
| Setting name | Description |
|---|---|
| Manager DN | Specify the value for the manager DistinguishedName attribute. |
| Add the top manager account to the group | Specify if the manager account should also be added to the Dynamic Group. |
| Levels of management hierarchy to include | Specify the levels of a management hierarchy to include. |
| More Parameters | |
| Query criteria | Query criteria are sent to the target platform with other query parameters to reduce the number of returned objects and may improve query performance. |
| Filter AD query results | Set the filtering conditions to only return objects or data that need to be processed by the rule. |
Result page size |
Specify the number of objects to include in one page for an AD DS query. |
| Result set size | Specify the number of objects to include in an AD DS query request. |
Comments
0 comments
Please sign in to leave a comment.