Overview
This rule queries Active Directory for user accounts based on the specified criteria. The rule grants target users the group memberships of a specified user account in addition to their existing memberships. This rule does not affect the existing memberships.
When to use this rule
Use this rule to grant the users the group memberships held by the specified Template Account.
Rule settings
Query Section
Setting name | Description |
---|---|
Limit scope to this domain or OU |
This setting defines the search query scope. To improve query performance, limit the scope to specific OU.
Important: To test rule configuration, limit the rule scope to an OU that contains test accounts or objects.
|
Account status |
Filter Active Directory user accounts by their status:
|
More Options |
|
Filter | To hide unwanted data set the filtering conditions here. |
Properties to display |
To display additional properties for each object found by the rule, add those properties to the list. |
Sort by | Sort result objects list. |
Action Section
Setting name | Description |
---|---|
Clone memberships from this user account
|
Specify user account DistinguishedName to clone its memberships. |
Output Section
This section defines the output format of this rule.
To get more information about this section, please see the Output section article.
Enforce/Schedule section
This section defines the schedule for how often to run the rule.
To get more information about this section, please see the Enforce/Schedule section article.
Change History
Version | Notes |
---|---|
12.1 | The rule description has been altered. |
9.3.0 | The rule is introduced in the product. |
Comments
0 comments
Please sign in to leave a comment.