hi,

On Wed, Apr 22, 2020 at 7:26 PM Natxo Asenjo <natxo.asenjo@gmail.com> wrote:

In order to use AD nested groups, do we need to add an external IDM group for every nested group?

specifically, our AD people have global groups (account groups, they say) with the user accounts, and the domain local groups (resource groups, they call them) have these global groups as members.

So, in order to grant the people on the domain local groups which have no direct user members, should we create both external groups in Idm? Both the global group and the domain local group?
--
Groeten,
natxo