AD Users | Add Users to Groups By OU
Rule description
This rule queries the Active Directory scope and moves users to specified Active Directory groups based on their membership in organizational units. Use the to manage group membership dynamically and ensure that users are consistently placed in correct groups based on their location within the directory structure.
When to use this rule
Use this rule to automate group management based on OU membership. This rule is ideal for scenarios where user groups need to reflect the organizational hierarchy or department structure in Active Directory. The rule is particularly useful in the following scenarios:
Department-based grouping: Automatically add users to department-specific groups based on their OU membership.
Access management: Use group membership for controlling access to resources like file shares or applications. The rule ensures that users in specific OUs are consistently added to the correct security or distribution groups.
Dynamic Group management: Simplify the management of Dynamic Groups by ensuring users are automatically added or removed from groups as they are moved between OUs in the Active Directory.
Rule settings
Query section
| Setting name | Description |
|---|---|
Limit scope to this domain or OU |
This setting defines the search query scope. To improve query performance, limit the scope to a specific OU. IMPORTANT: To test the rule configuration, limit the rule scope to an OU that contains test accounts or objects and use the Preview feature. |
Query criteria |
Query criteria are sent with the query and may improve query performance. TIP: For additional information on the criteria builder, see the How to use Query Builder dialog for Query Criteria and Filter rule settings. |
Select Data Source |
Specify the text file to be imported. The […] (three dots) button allows the user to browse for the file and the Create/Edit button allows the creation or editing of the existing file in the built-in Data Source editor. |
Separator used in file |
Specify the separator used in the source CSV file. |
More options | |
| Filter | Define filter conditions, if needed. |
Action section
| Setting name | Description |
|---|---|
AD group (DN) |
Define AD groups to add queried users to. Split group DNs with semicolons when you specify multiple groups; alternatively, use the built-in wizard to select groups. IMPORTANT: This setting overrides the data of the CSV text file. Instead of the organizational units defined in the CSV files, the rule uses the Query settings to define the scope. |
Output section
This section defines the output format of this rule.
To get more information about this section, please see the Rule Output section article.
Enforce/Schedule section
This section defines the schedule for how often to run the rule.
To get more information about this section, please see the Rule Enforce/Schedule section article.
Comments
0 comments
Please sign in to leave a comment.