Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Additional AD groups are reconciling which are not part of advanceGroupFilter but memberOf accounts

BalajiE
New Contributor
New Contributor

Hi Team,

We have a requirement to reconcile only few OU groups in Active Directory. But few additional groups are reconciling which are memberOf some accounts.

We need to reconcile only Application and Server OUs. Which is defined in  advanceGroupFilter. As observed, we are getting additional groups from Domain OU due to some users which we reconcile are having memberOf of Domain groups.

BalajiE_0-1723118479318.png

"advanceGroupFilter": {
"memberOf": {
"OU=Server,OU=Security Groups,DC=XXX": [
"(&(objectClass=group))"
],
"OU=Application,OU=Security Groups,DC=XXX": [
"(&(objectClass=group))"
]
}

Customer don't want to reconcile these additional groups which Saviynt is not managing. Please let us know, how we restrict these additional groups.

 

Who Me Too'd this topic